In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/opencrx/opencrx/commit/14e75f95e5f56fbe7ee897bdf5d858788072e818 | Patch Tool Signature | 
| https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25959 | Tool Signature | 
Configurations
                    History
                    No history.
Information
                Published : 2021-09-29 14:15
Updated : 2021-10-07 13:21
NVD link : CVE-2021-25959
Mitre link : CVE-2021-25959
CVE.ORG link : CVE-2021-25959
JSON object : View
Products Affected
                opencrx
- opencrx
 
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
