PT-2021-16898 · Publify · Publify

Published

2021-11-10

·

Updated

2024-03-06

·

CVE-2021-25974

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Publify versions v8.0 through v9.2.4
Description The issue allows a user with a publisher role to inject and execute arbitrary JavaScript code, enabling stored XSS attacks. This can occur while creating a page or article, potentially through unrestricted file upload, which permits malicious JavaScript injection via uploaded HTML files.
Recommendations For Publify versions v8.0 through v9.2.4, consider restricting file uploads or validating the content of uploaded files to prevent malicious code execution until a patch is available. As a temporary workaround, limiting the privileges of the publisher role may help minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PUBLIFY-2021-25974
BIT-PUBLIFY-2021-25975
CVE-2021-25974
GHSA-3H7V-WQW7-FF28
GHSA-WMH9-X28J-C6GR

Affected Products

Publify