Record summary

CVE-2021-47925 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachments in the classes endpoint, which execute when other users view the affected records or preview attachments.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListCMDBuild 3.3.2affected

Proofs of concept

1

Catalogued exploits

ExploitDBCMDBuild 3.3.2 - 'Multiple' Cross Site Scripting (XSS)ExploitDB exploitby Hosein VitaNot analyzed1 file
ExploitDB

PoC details

References

5