CVE-2021-21319
Summary
| CVE | CVE-2021-21319 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-25 16:15:00 UTC |
| Updated | 2021-10-28 01:12:00 UTC |
| Description | Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled as a workaround (this is the default state). Malicious javascript code can be executed (not stored) on login and retrieve password pages. This issue is patched in version 0.9.5. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prevent some possible XSS · galette/galette@514418d · GitHub | MISC | github.com | |
| Galette bugs & features | MISC | bugs.galette.eu | |
| Fix stored XSS on dynamic fields configuration · galette/galette@8f3bdd9 · GitHub | MISC | github.com | |
| Several stored XSS · Advisory · galette/galette · GitHub | CONFIRM | github.com | |
| Add test on stored xss · galette/galette@f54b257 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.