CVE-2021-21283

Source
https://cve.org/CVERecord?id=CVE-2021-21283
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21283.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-21283
Aliases
Published
2021-01-26T21:15:12Z
Modified
2026-07-08T06:00:14Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site scripting vulnerability. A change in release beta 14 of the Sticky extension caused the plain text content of the first post of a pinned discussion to be injected as HTML on the discussion list. The issue was discovered following an internal audit. Any HTML would be injected through the m.trust() helper. This resulted in an HTML injection where

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:a:flarum:sticky:0.1.0:beta14:*:*:*:*:*:*",
                "cpe:2.3:a:flarum:sticky:0.1.0:beta15:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "0.1.0-beta14"
                },
                {
                    "last_affected": "0.1.0-beta14"
                },
                {
                    "introduced": "0.1.0-beta15"
                },
                {
                    "last_affected": "0.1.0-beta15"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "flarum:sticky"
        }
    ]
}
References

Affected packages

Git / github.com/flarum/sticky

Affected ranges

Type
GIT
Repo
https://github.com/flarum/sticky
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.15
v0.1.0-beta.3
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21283.json"