CVE-2021-3294: Casap Automated Enrollment System Project Casap Automated Enrollment System
Medium severity, CVSS 5.4. EPSS: 2.8% chance of exploitation in the next 30 days.
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.
Affected products
- Casap Automated Enrollment System Project Casap Automated Enrollment System: version 1.0 only
Published 2021-02-09. Last modified 2026-07-09.