In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Mend
Published: 2021-05-24T10:54:10
Updated: 2024-08-03T20:11:28.489Z
Reserved: 2021-01-22T00:00:00
Link: CVE-2021-25938
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-24T11:15:08.470
Modified: 2024-11-21T05:55:38.397
Link: CVE-2021-25938
Redhat
No data.