Several stored XSS
Vulnerability Description
Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, malicious javascript code can be stored to be displayed later on self subscription page. The self subscription feature can be disabled as a workaround (this is the default state). Malicious javascript code can be executed (not stored) on login and retrieve password pages. This issue is patched in version 0.9.5.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-21319
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/galette/galette/security/advisories/GHSA-vjc9-mj44-x59q
- https://github.com/galette/galette/commit/514418da973ae5b84bf97f94bd288a41e8e3f0a6
- https://github.com/galette/galette/commit/8f3bdd9f7d0708466e011253064a867ca2b271a5
- https://github.com/galette/galette/commit/f54b2570615d38d0302e937079233e52c2d80995
- https://bugs.galette.eu/issues/1535
More from galette
View All →Affected Vendor
galette
View all reports →