Description
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0583 | The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API. |
Github GHSA |
GHSA-x347-fc9w-w7c3 | Nuxeo vulnerable to Reflected Cross-Site Scripting leading to Remote Code Execution |
References
History
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:32:27.606Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32828
Updated: 2024-08-03T23:33:55.936Z
Status : Modified
Published: 2023-01-05T23:15:09.033
Modified: 2024-11-21T06:07:50.090
Link: CVE-2021-32828
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA