SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21319

In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page.

MEDIUM 5.4EPSS 0.89%

Does this matter?

Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.

Description

Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled as a workaround (this is the default state). Malicious javascript code can be executed (not stored) on login and retrieve password pages. This issue is patched in version 0.9.5.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.89% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
galette/galette
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.