CVE-2021-25978

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/11/2021
Last modified:
09/11/2021

Description

Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apostrophecms:apostrophecms:*:*:*:*:*:*:*:* 2.63.0 (including) 3.3.1 (including)