Description
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12795 | In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-08-03T20:11:28.489Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25938
No data.
Status : Modified
Published: 2021-05-24T11:15:08.470
Modified: 2024-11-21T05:55:38.397
Link: CVE-2021-25938
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD