Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.
References
Link | Resource |
---|---|
https://github.com/apostrophecms/apostrophe/commit/c8b94ee9c79468f1ce28e31966cb0e0839165e59 | Patch Third Party Advisory |
Configurations
Information
Published : 2021-11-07 10:15
Updated : 2021-11-09 10:21
NVD link : CVE-2021-25978
Mitre link : CVE-2021-25978
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
apostrophecms
- apostrophecms