PT-2021-16892 · Opencms · Opencms
Published
2021-10-19
·
Updated
2021-10-21
·
CVE-2021-25968
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenCMS versions 10.5.0 through 11.0.2
Description
The issue allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.
Recommendations
For OpenCMS versions 10.5.0 through 11.0.2, consider disabling the Sitemap functionality until a patch is available to prevent the storage and execution of malicious scripts. Restrict access to the Sitemap feature to minimize the risk of exploitation. Avoid using the vulnerable field in the Sitemap functionality until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencms