Vulnerabilities > Leostream > Connection Broker > 9.0.10

DATE CVE VULNERABILITY TITLE RISK
2021-08-06 CVE-2021-38157 Cross-site Scripting vulnerability in Leostream Connection Broker 9.0.10/9.0.3/9.0.34
LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter.
network
low complexity
leostream CWE-79
6.1