Description
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
No analysis available yet.
Remediation
Vendor Solution
Update version to v7.32 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12815 | In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe. |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:43:55.017Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25990
Updated: 2024-08-03T20:19:19.260Z
Status : Modified
Published: 2021-12-29T09:15:09.363
Modified: 2024-11-21T05:55:44.830
Link: CVE-2021-25990
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD