CVE detail
CVE-2021-26832 — CVE-2021-26832
Published 2021-04-14 · Modified 2026-06-17 · Vendor priority-software · Product priority_enterprise_management_system · Source nvd
MEDIUM
severity
CVSS-derived band
0.0085
EPSS probability
exploitation probability, 30d
55.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References