6.8

CVE-2021-21319

Several stored XSS

Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled as a workaround (this is the default state). Malicious javascript code can be executed (not stored) on login and retrieve password pages. This issue is patched in version 0.9.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GaletteGalette Version < 0.9.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.536
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
security-advisories@github.com 6.8 2.3 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://bugs.galette.eu/issues/1535
Vendor Advisory
Permissions Required
https://github.com/galette/galette/commit/514418da973ae5b84bf97f94bd288a41e8e3f0a6
Patch
Third Party Advisory
https://github.com/galette/galette/commit/8f3bdd9f7d0708466e011253064a867ca2b271a5
Patch
Third Party Advisory
https://github.com/galette/galette/commit/f54b2570615d38d0302e937079233e52c2d80995
Patch
Third Party Advisory
https://github.com/galette/galette/security/advisories/GHSA-vjc9-mj44-x59q
Third Party Advisory