Description
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
No analysis available yet.
Remediation
Vendor Solution
Update to 5.2.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2111 | In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance. |
Github GHSA |
GHSA-rwh9-8xx8-4wfm | Cross-site Scripting in OpenCRX |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-16T19:24:15.717Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25959
No data.
Status : Modified
Published: 2021-09-29T14:15:07.620
Modified: 2024-11-21T05:55:40.650
Link: CVE-2021-25959
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA