CVE-2021-25893: XSS
Published Apr 2, 2021
·Updated
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.
Affected Software
2 affected components
Magnolia-cms Magnolia Cms>=6.1.3<6.1.7
Magnolia-cms Magnolia Cms>=6.2.3<6.2.4
Event History
Apr 2, 2021
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25893?
CVE-2021-25893 is classified as a medium severity vulnerability due to its stored cross-site scripting (XSS) nature.
2
How do I fix CVE-2021-25893?
To fix CVE-2021-25893, upgrade Magnolia CMS to version 6.2.4 or later.
3
What versions of Magnolia CMS are affected by CVE-2021-25893?
CVE-2021-25893 affects Magnolia CMS versions from 6.1.3 to 6.2.3.
4
Can CVE-2021-25893 lead to data compromise?
Yes, CVE-2021-25893 can lead to data compromise by allowing attackers to execute malicious scripts in users' browsers.
5
Is there a workaround for CVE-2021-25893?
There are no known workarounds for CVE-2021-25893, and the recommended action is to apply the available patch.