CVE-2021-32853

CVSS V2 None CVSS V3 None
Description
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.
Overview
  • CVE ID
  • CVE-2021-32853
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-20T23:15:12
  • Last Modified Date
  • 2023-03-02T15:56:09
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:erxes:erxes:*:*:*:*:*:*:*:* 1 OR 0.22.3
History
Created Old Value New Value Data Type Notes
2023-04-17 08:00:31 Added to TrackCVE
2023-04-17 08:00:33 Weakness Enumeration new