Lucene search

K
osvGoogleOSV:CVE-2021-25977
HistoryOct 25, 2021 - 1:15 p.m.

CVE-2021-25977

2021-10-2513:15:07
Google
osv.dev
3
piranhacms
vulnerability
stored xss
page title
low privileged user
javascript execution

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

19.5%

In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

19.5%

Related for OSV:CVE-2021-25977