Description
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update version to v7.32 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12814 | In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them. |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:44:01.727Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25989
Updated: 2024-08-03T20:19:19.395Z
Status : Modified
Published: 2021-12-29T09:15:09.267
Modified: 2024-11-21T05:55:44.700
Link: CVE-2021-25989
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD