CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachments in the classes endpoint, which execute when other users view the affected records or preview attachments.
References
Configurations
No configuration.
History
25 Jul 2026, 11:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-10 13:16
Updated : 2026-07-25 11:10
NVD link : CVE-2021-47925
Mitre link : CVE-2021-47925
CVE.ORG link : CVE-2021-47925
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
