Description
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.
No analysis available yet.
Remediation
Vendor Solution
Update to v9.2.5
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2187 | In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. |
Github GHSA |
GHSA-3h7v-wqw7-ff28 | Cross site scripting in publify |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:52:22.378Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25975
Updated: 2024-08-03T20:19:19.334Z
Status : Modified
Published: 2021-11-10T11:15:09.197
Modified: 2026-06-17T03:42:42.723
Link: CVE-2021-25975
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA