6.1
CVE-2025-68115
- EPSS 0.21%
- Veröffentlicht 16.12.2025 00:56:23
- Zuletzt bearbeitet 07.10.2026 19:10:00
- Erkennungen
Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 8.6.1
Parseplatform ≫ Parse-server Version 9.0.0 Update - SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha10 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha11 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha7 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha8 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.0.0 Update alpha9 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.1.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.1.0 Update alpha2 SwPlatform node.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.119 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| security-advisories@github.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/parse-community/parse-server/pull/9985
https://github.com/parse-community/parse-server/pull/9986
https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv