Vulnerabilities > Draytek > Vigorconnect > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-13 CVE-2021-20128 Cross-site Scripting vulnerability in Draytek Vigorconnect 1.6.0
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.
network
low complexity
draytek CWE-79
5.4