{"id":"CVE-2021-4121","aliases":["GHSA-j85f-xw9x-ffwp"],"url":"https://o3.security/vulnerability/CVE-2021-4121","summary":"yetiforcecrm is vulnerable to Cross-site Scripting","details":"yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","published":"2021-12-16T08:15:07.827Z","modified":"2026-07-08T23:57:57.567729Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"yetiforce/yetiforce-crm","fixedVersion":null}],"fix":{"url":"https://github.com/yetiforcecompany/yetiforcecrm/commit/6b5967198e43b6fbb3b2715b49c6cd5b12ce08c3","label":"yetiforcecompany/yetiforcecrm@6b59671"},"references":[{"type":"FIX","url":"https://github.com/yetiforcecompany/yetiforcecrm/commit/6b5967198e43b6fbb3b2715b49c6cd5b12ce08c3"},{"type":"FIX","url":"https://huntr.dev/bounties/6da878de-acdb-4b97-b9ff-9674c3f0881d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T23:57:57.567729Z"}}