PT-2021-16892 · Opencms · Opencms

Published

2021-10-19

·

Updated

2021-10-21

·

CVE-2021-25968

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCMS versions 10.5.0 through 11.0.2
Description The issue allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.
Recommendations For OpenCMS versions 10.5.0 through 11.0.2, consider disabling the Sitemap functionality until a patch is available to prevent the storage and execution of malicious scripts. Restrict access to the Sitemap feature to minimize the risk of exploitation. Avoid using the vulnerable field in the Sitemap functionality until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25968

Affected Products

Opencms