Description
In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 12.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12806 | In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field. |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T16:00:50.132Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25968
Updated: 2024-08-03T20:19:18.982Z
Status : Modified
Published: 2021-10-19T09:15:07.853
Modified: 2024-11-21T05:55:41.840
Link: CVE-2021-25968
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD