CVE-2021-30170
Status: ModifiedMedium (5.4)—
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Base score: 5.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.59%
- Percentile among all scored CVEs: 46
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
Raw JSON (NVD)
Show
{
"id": "CVE-2021-30170",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.6,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "Jun-He Technology Ltd.",
"product": "ERP POS",
"versions": [
{
"status": "affected",
"version": "2013.10"
}
]
}
]
}
],
"published": "2021-05-07T10:15:08.430",
"references": [
{
"url": "https://www.twcert.org.tw/tw/cp-132-4707-9c87e-1.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-4707-9c87e-1.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information."
},
{
"lang": "es",
"value": "Los caracteres especiales de la página de perfil de cliente de ERP POS no se filtran en la entrada de los usuarios, lo que permite a atacantes autenticados remotos poder inyectar JavaScript malicioso y ejecutar ataques de tipo XSS (Cross-site scripting) Almacenado, además de acceder y manipular la información del cliente"
}
],
"lastModified": "2026-06-17T03:49:47.447",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:junhetec:enterprise_resource_planning_point_of_sale_system:2013.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E635C622-D09C-423B-8800-05848E85C439"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "twcert@cert.org.tw"
}