---
id: CVE-2021-46355
title: OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS)
summary: >-
  OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the
  vulnerability, the attacker needs to manipulate the name of some device on
  your computer, such as a printer, replacing the device name with some
  malicious code…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: factorfx
product: ocs_inventory
affected:
  - ocs_inventory = 2.9.1
published: '2022-02-11'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-46355'
references:
  - url: >-
      https://medium.com/@windsormoreira/ocs-inventory-2-9-1-cross-site-scripting-xss-cve-2021-46355-a88d72606b7e
    label: cve@mitre.org
  - url: 'http://ocs.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://medium.com/%40windsormoreira/ocs-inventory-2-9-1-cross-site-scripting-xss-cve-2021-46355-a88d72606b7e
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00781
epssPercentile: 0.54493
ingestedAt: '2026-07-06T17:03:23.900Z'
---

## Overview

OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with some malicious code that allows the execution of Stored Cross-site Scripting (XSS).

## Affected

- `ocs_inventory = 2.9.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
