LiveActive security incident?Get immediate response
CVE Record

CVE-2021-25959: OpenCRX - Reflected Cross-Site Scripting in Password Reset Functionality

In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.

MediumCVSS 6.1Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-25959 is a reflected XSS issue in openCRX password reset functionality. A malicious link or interaction could make a user’s browser run attacker-supplied JavaScript in the openCRX context, risking limited data exposure or unauthorized actions as that user.

Executive priority

Prioritize remediation in the next normal patch cycle, faster for public-facing openCRX systems. This is not evidenced as actively exploited, but it can affect user trust and session integrity if abused through phishing or targeted user interaction.

Technical view

OpenCRX versions v4.0.0 through v5.1.0 are reported vulnerable to CWE-79 through unsanitized password reset parameters. The CVSS 3.1 score is 6.1, with network attack vector, low complexity, no privileges required, user interaction required, changed scope, and low confidentiality and integrity impact.

Likely exposure

Exposure is most likely where openCRX v4.0.0 through v5.1.0 is deployed and password reset pages are reachable. The bundle’s affected entry specifically names org.opencrx opencrx-core-config 4.0.0, so teams should verify exact installed versions and components.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation evidence. Exploitation requires user interaction and depends on the vulnerable password reset workflow. Treat internet-facing or externally accessible openCRX portals as higher priority for review.

Researcher notes

Evidence supports reflected XSS in password reset parameters, not remote code execution or authentication bypass. The source bundle includes a broad version range and one specific affected package entry, so product-version mapping should be validated before declaring systems affected or clean.

Mitigation direction

  • Check openCRX vendor guidance and the referenced fixing commit.
  • Upgrade openCRX beyond affected versions where vendor-supported releases are available.
  • Restrict access to password reset functionality if exposure cannot be promptly remediated.
  • Apply standard XSS defenses for input handling and output encoding in custom deployments.

Validation and detection

  • Inventory openCRX deployments and confirm exact application versions.
  • Confirm whether password reset functionality is externally reachable.
  • Review application code or release history for the referenced commit.
  • Run authorized regression testing for reflected XSS in the reset workflow.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-25959 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.1CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N2.82.7Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

6.1Medium
CVSS 3.1 vector shape for CVE-2021-25959Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
org.opencrxopencrx-core-config4.0.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-79 · source CWE mapping

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.