Back to Database
Status published
Medium
CVE-2021-25990
ifme - Stored Cross-Site Scripting (XSS) in Contacts section
Vulnerability Description
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25990
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- WhiteSource Vulnerability Research Team (WVR)
References
More from ifmeorg
View All →CVE-2021-25992
ifme - Insufficient Session Expiration
Critical
9.8
CVE-2021-25991
ifme - Improper Access Control leads to admin deactivation
Medium
5.7
CVE-2021-25989
ifme - Stored Cross-Site Scripting (XSS) in Groups section
Medium
5.4
CVE-2021-25988
ifme - Stored Cross-Site Scripting (XSS) in Notifications section
Medium
5.4
Affected Vendor
ifmeorg
View all reports →Affected Software
ifme
Vulnerable Versions:
v7.22.0, unspecified
Timeline
Official Publish:
December 29th, 2021
Last Modified:
April 30th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N