Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0042 | In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s browser when they open the malicious profile picture |
Github GHSA |
GHSA-6w9p-88qg-p3g3 | Cross-site Scripting in CKAN |
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:44:12.543Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25967
Updated: 2024-08-03T20:19:19.015Z
Status : Modified
Published: 2021-12-01T14:15:07.737
Modified: 2024-11-21T05:55:41.713
Link: CVE-2021-25967
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA