In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NIf Me Ifme
APPIf-Me7.22.0 – 7.31.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2021-25992CRITICAL9.8PL ✓same product
If-Me Ifme: brak unieważnienia sesji po wylogowaniu użytkownika
CVE-2021-25988MEDIUM5.4same product
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) w...
CVE-2021-25989MEDIUM5.4same product
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. I...
CVE-2021-25991MEDIUM5.7same product
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible f...