{"id":"GHSA-g9ph-r9hc-34r8","summary":"Erxes vulnerable to Cross-site Scripting","details":"Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in all versions. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.","aliases":["CVE-2021-32853"],"modified":"2023-11-08T04:06:02.417171Z","published":"2023-02-21T00:30:20Z","database_specific":{"nvd_published_at":"2023-02-20T23:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-02-22T19:16:24Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32853"},{"type":"PACKAGE","url":"https://github.com/erxes/erxes"},{"type":"WEB","url":"https://github.com/erxes/erxes/blob/f131b49add72032650d483f044d00658908aaf4a/widgets/server/index.ts#L54"},{"type":"WEB","url":"https://github.com/erxes/erxes/blob/f131b49add72032650d483f044d00658908aaf4a/widgets/server/views/widget.ejs#L14"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2021-103-erxes"}],"affected":[{"package":{"name":"erxes","ecosystem":"npm","purl":"pkg:npm/erxes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-g9ph-r9hc-34r8/GHSA-g9ph-r9hc-34r8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}