CVE-2021-21319
In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page.
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled as a workaround (this is the default state). Malicious javascript code can be executed (not stored) on login and retrieve password pages. This issue is patched in version 0.9.5.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- galette/galette
- Source
- security-advisories@github.com
References
- https://bugs.galette.eu/issues/1535Permissions Required, Vendor Advisory
- https://github.com/galette/galette/commit/514418da973ae5b84bf97f94bd288a41e8e3f0a6Patch, Third Party Advisory
- https://github.com/galette/galette/commit/8f3bdd9f7d0708466e011253064a867ca2b271a5Patch, Third Party Advisory
- https://github.com/galette/galette/commit/f54b2570615d38d0302e937079233e52c2d80995Patch, Third Party Advisory
- https://github.com/galette/galette/security/advisories/GHSA-vjc9-mj44-x59qThird Party Advisory
- https://bugs.galette.eu/issues/1535Permissions Required, Vendor Advisory
- https://github.com/galette/galette/commit/514418da973ae5b84bf97f94bd288a41e8e3f0a6Patch, Third Party Advisory
- https://github.com/galette/galette/commit/8f3bdd9f7d0708466e011253064a867ca2b271a5Patch, Third Party Advisory
- https://github.com/galette/galette/commit/f54b2570615d38d0302e937079233e52c2d80995Patch, Third Party Advisory
- https://github.com/galette/galette/security/advisories/GHSA-vjc9-mj44-x59qThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.