CVE-2021-25984: FactorJS - Stored Cross-Site Scripting (XSS) in Post Reply Functionality
Published Nov 16, 2021
·Updated
In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site Scripting (XSS) at the “post reply” section. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.
Affected Software
1 affected component
Darwin Factor Node.js>=1.3.3<=1.8.30
Remediation
Information
No fix is provided
Event History
Nov 16, 2021
CVE Published
via MITRE·09:45 AM
Data Sourced
via MITRE·09:45 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-25984.
2
What is the severity of CVE-2021-25984?
The severity of CVE-2021-25984 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2021-25984?
The affected software for CVE-2021-25984 is Factor (App Framework & Headless CMS) forum plugin versions v1.3.3 to v1.8.30.
4
What is the impact of CVE-2021-25984?
The impact of CVE-2021-25984 is the execution of malicious JavaScript code and theft of session cookies.
5
Is authentication required to exploit CVE-2021-25984?
No, authentication is not required to exploit CVE-2021-25984.