First published: Tue Nov 16 2021(Updated: )
In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site Scripting (XSS) at the “post reply” section. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
Darwin Factor | >=1.3.3<=1.8.30 |
No fix is provided
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-25984.
The severity of CVE-2021-25984 is medium with a CVSS score of 6.1.
The affected software for CVE-2021-25984 is Factor (App Framework & Headless CMS) forum plugin versions v1.3.3 to v1.8.30.
The impact of CVE-2021-25984 is the execution of malicious JavaScript code and theft of session cookies.
No, authentication is not required to exploit CVE-2021-25984.