CVE-2021-3294: Casap Automated Enrollment System Project Casap Automated Enrollment System

Medium severity, CVSS 5.4. EPSS: 2.8% chance of exploitation in the next 30 days.

CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.

Affected products

Published 2021-02-09. Last modified 2026-07-09.