{"id":"GHSA-jvjp-vh27-r9h5","summary":"Cross-site Scripting in PiranhaCMS","details":"In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution. ","aliases":["CVE-2021-25977"],"modified":"2023-11-01T04:54:49.891965Z","published":"2021-10-27T18:53:03Z","database_specific":{"nvd_published_at":"2021-10-25T13:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-10-26T17:55:07Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25977"},{"type":"WEB","url":"https://github.com/PiranhaCMS/piranha.core/commit/543bc53c7dbd28c793ec960b57fb0e716c6b18d7"},{"type":"PACKAGE","url":"https://github.com/PiranhaCMS/piranha.core"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25977"}],"affected":[{"package":{"name":"Piranha","ecosystem":"NuGet","purl":"pkg:nuget/Piranha"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"9.2.0"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.0.3","7.1.0","8.0.0","8.0.1","8.0.2","8.1.0","8.2.0","8.3.0","8.4.0","8.4.1","8.4.2","9.0.0","9.0.0-beta1","9.0.0-rc1","9.0.0-rc2","9.0.1","9.1.0","9.1.0-alpha1","9.1.0-alpha2","9.1.0-beta1","9.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-jvjp-vh27-r9h5/GHSA-jvjp-vh27-r9h5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}