First published: Tue Sep 21 2021(Updated: )
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
Opencrx Opencrx | >=4.0.0<=5.1.0 |
Update to 5.2.0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25959 is a vulnerability in OpenCRX versions v4.0.0 through v5.1.0 that allows for reflected Cross-site Scripting (XSS).
CVE-2021-25959 affects OpenCRX by enabling execution of external javascript files through unsanitized parameters in the password reset functionality.
CVE-2021-25959 is considered a medium severity vulnerability with a severity value of 6.1.
The CWE ID for CVE-2021-25959 is CWE-79.
To fix CVE-2021-25959 in OpenCRX, update to a version beyond v5.1.0, which includes the fix for the reflected Cross-site Scripting (XSS) vulnerability.