S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-32853 Scanner

CVE-2021-32853 scanner - Cross-Site Scripting (XSS) vulnerability in npm Erxes

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-32853
9.6
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
erxesby npm
0.22.3
Updated Aug 21, 2026View on NVD →
Detail

Erxes is a powerful and versatile experience operating system (XOS) designed to streamline communication, collaboration, and marketing automation for businesses of all sizes. It comes with a set of plugins that allow users to manage everything from lead generation and email marketing to customer engagement and support. Erxes can be accessed via a web interface or mobile app, giving users the freedom to work from anywhere. With its intuitive and customizable interface, Erxes is ideal for teams looking to improve their productivity and customer experience.

CVE-2021-32853 is a vulnerability that affects Erxes in versions 0.22.3 and prior. This vulnerability is caused by a cross-site scripting (XSS) issue that could allow a malicious user to execute client-side code on the victim's system. To exploit this vulnerability, the victim must either follow a malicious link or be redirected to a malicious website. This vulnerability could allow an attacker to steal sensitive data or compromise the entire system.

If exploited, CVE-2021-32853 could lead to serious consequences for businesses that rely on Erxes. An attacker could gain access to sensitive customer data like email addresses, phone numbers, and credit card information. They could also compromise the entire system and disrupt business operations. Furthermore, this vulnerability could damage a business's reputation, eroding customer trust and loyalty.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers advanced security scanning and reporting tools that can help businesses identify and fix security vulnerabilities before they are exploited. With its user-friendly interface and comprehensive reporting capabilities, s4e.io is the ideal solution for businesses looking to stay one step ahead of cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Updating the version of Erxes to the latest one that is not vulnerable to this exploit.
  • Implementing web application firewalls and network-level firewalls to restrict unauthorized access and ensure safe data transmission.
  • Actively monitoring system logs for signs of suspicious activity.
  • Regularly conducting vulnerability scans and penetration testing to identify and remediate potential security flaws.
  • Educating employees about proper cyber hygiene practices and cautioning them before clicking on links from unknown sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-32853 scanner - Cross-Site Scripting (XSS) vulnerability in npm Erxes | S4E