Lucene search

K
cvelistMendCVELIST:CVE-2021-25974
HistoryNov 10, 2021 - 11:10 a.m.

CVE-2021-25974 Publify - Stored Cross-Site Scripting (XSS) in Editor

2021-11-1011:10:12
CWE-79
Mend
www.cve.org
2
publify
vulnerability
stored
cross-site scripting
xss
editor
javascript
injection
page
article

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

19.4%

In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.

CNA Affected

[
  {
    "product": "publify_core",
    "vendor": "publify_core",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "v8.0",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "v9.2.4",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

19.4%

Related for CVELIST:CVE-2021-25974