First published: Tue Nov 16 2021(Updated: )
In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “search” parameter in the URL. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
Darwin Factor | >=1.3.5<=1.8.30 |
No fix is provided
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25982 is a vulnerability in Factor (App Framework & Headless CMS) forum plugin versions 1.3.5 to 1.8.30 that allows for reflected Cross-Site Scripting (XSS) attacks.
The severity of CVE-2021-25982 is medium, with a severity value of 6.1.
An unauthenticated attacker can exploit CVE-2021-25982 by injecting malicious JavaScript code through the 'search' parameter in the URL, potentially stealing session cookies.
Versions 1.3.5 to 1.8.30 of the Factor forum plugin are affected by CVE-2021-25982.
To mitigate CVE-2021-25982, it is recommended to upgrade to a version of the Factor forum plugin that is not affected by the vulnerability.