Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2021-37469

Disclosure Date: July 25, 2021 (last updated February 23, 2025)
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.
Attacker Value
Unknown

CVE-2021-37470

Disclosure Date: July 25, 2021 (last updated February 23, 2025)
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.