VYPR
Medium severity6.1NVD Advisory· Published May 24, 2021· Updated Jun 17, 2026

CVE-2021-25938

CVE-2021-25938

Description

In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • ArangoDB/ArangoDB2 versions
    cpe:2.3:a:arangodb:arangodb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:arangodb:arangodb:*:*:*:*:*:*:*:*range: >=2.2.6.2,<=3.7.10
    • (no CPE)range: v2.2.6.2 - v3.7.10
  • ArangoDB/ArangoDBdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.