In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
History

Wed, 30 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mend

Published: 2021-12-29T09:10:14.710Z

Updated: 2025-04-30T15:44:07.124Z

Reserved: 2021-01-22T00:00:00.000Z

Link: CVE-2021-25988

cve-icon Vulnrichment

Updated: 2024-08-03T20:19:19.487Z

cve-icon NVD

Status : Modified

Published: 2021-12-29T09:15:09.150

Modified: 2024-11-21T05:55:44.560

Link: CVE-2021-25988

cve-icon Redhat

No data.