CVE-2021-25959

MEDIUM

OpenCRX 4.0.0-5.1.0 - Reflected Cross-Site Scripting via Password Reset Parameters

Title source: llm
STIX 2.1

Description

In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.

Scores

CVSS v3 6.1
EPSS 0.0084
EPSS Percentile 53.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (6)
opencrx/opencrx 4.0.0 - 5.1.0
org.opencrx/opencrx-client 4.0.0 - 5.2.0Maven
org.opencrx/opencrx-core 4.0.0 - 5.2.0Maven
org.opencrx/opencrx-core-config 4.0.0 - 5.2.0Maven
org.opencrx/opencrx-core-models 4.0.0 - 5.2.0Maven
org.opencrx/opencrx-gradle 4.0.0 - 5.2.0Maven
Published Sep 29, 2021
Tracked Since Feb 18, 2026