6.1

CVE-2025-68115

Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 8.6.1
Parseplatform ≫ Parse-server Version 9.0.0 Update - SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha10 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha11 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha7 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha8 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha9 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.1.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.1.0 Update alpha2 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.119
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security-advisories@github.com 5.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/parse-community/parse-server/pull/9985
Patch
Issue Tracking
https://github.com/parse-community/parse-server/pull/9986
Patch
Issue Tracking
https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv
Vendor Advisory