CVE-2021-25959
29.09.2021, 14:15
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
Vendor | Product | Version |
---|---|---|
opencrx | opencrx | 4.0.0 ≤ 𝑥 ≤ 5.1.0 |
𝑥
= Vulnerable software versions
References