CVE-2021-25969
Last modified
CVE-2021-25969 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tuzitio | Camaleon Cms | >= 0.0.1, <= 2.6.0 |
References
- https://github.com/owen2345/camaleon-cms/commit/05506e9087bb05282c0bae6ccfe0283d0332ab3cPatch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25969Third Party Advisory
- https://github.com/owen2345/camaleon-cms/commit/05506e9087bb05282c0bae6ccfe0283d0332ab3cPatch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25969Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-25969?
How severe is CVE-2021-25969?
How do I fix CVE-2021-25969?
Are you affected by CVE-2021-25969?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
