Vulnerability Description
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opencrx | Opencrx | >= 4.0.0, <= 5.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/opencrx/opencrx/commit/14e75f95e5f56fbe7ee897bdf5d858788072e8PatchTool Signature
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25959Tool Signature
- https://github.com/opencrx/opencrx/commit/14e75f95e5f56fbe7ee897bdf5d858788072e8PatchTool Signature
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25959Tool Signature
FAQ
What is CVE-2021-25959?
CVE-2021-25959 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external ...
How severe is CVE-2021-25959?
CVE-2021-25959 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25959?
Check the references section above for vendor advisories and patch information. Affected products include: Opencrx Opencrx.