← back
CVE-2021-32853

Erxes vulnerable to Cross-site Scripting

CVSS 6.1 MEDIUMEPSS 3.1%CWE-79
In short

Erxes allows attackers to inject malicious code that runs in users' browsers when they visit a specially crafted link. This can let attackers steal sensitive information or perform actions on behalf of the victim.

Technical detail

Reflected cross-site scripting (XSS) vulnerability in Erxes versions ≤0.22.3 requires user interaction (clicking a malicious link or being redirected). Attack vector is network-based with low attack complexity; successful exploitation results in client-side code execution within the victim's browser context.

Summary generated and translated by AI from the official description.
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
npm · erxes

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →