First published: Tue Oct 19 2021(Updated: )
In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCMS | >=10.5.0<11.0.2 |
Update to 12.0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-25968.
The affected software is OpenCMS versions 10.5.0 to 11.0.2.
The severity of CVE-2021-25968 is medium with a CVSS score of 5.4.
CVE-2021-25968 allows low privileged application users to store malicious scripts in the Sitemap functionality of OpenCMS, which are executed in a victim’s browser when they open the page containing the vulnerable field.
To fix CVE-2021-25968, it is recommended to update OpenCMS to a version beyond 11.0.2 or apply the necessary patches provided by the vendor.