Lucene search

K
cveMendCVE-2021-25987
HistoryNov 30, 2021 - 2:15 p.m.

CVE-2021-25987

2021-11-3014:15:07
CWE-79
Mend
web.nvd.nist.gov
18
hexo
vulnerability
stored xss
cve-2021-25987
nvd

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

4.7

Confidence

High

EPSS

0

Percentile

12.6%

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

Affected configurations

Nvd
Node
hexohexoRange0.0.15.4.0node.js
VendorProductVersionCPE
hexohexo*cpe:2.3:a:hexo:hexo:*:*:*:*:*:node.js:*:*

CNA Affected

[
  {
    "product": "Hexo",
    "vendor": "Hexo",
    "versions": [
      {
        "lessThanOrEqual": "5.4.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "next of 0.0.1",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

4.7

Confidence

High

EPSS

0

Percentile

12.6%