CVE-2021-25978

MEDIUM

Apostrophecms < 3.3.1 - XSS

Title source: rule
STIX 2.1

Description

Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
apostrophecms/apostrophecms 2.63.0 - 3.3.1
npm/apostrophe 2.63.0 - 3.4.0npm
Published Nov 07, 2021
Tracked Since Feb 18, 2026