Junglewise Threat Intelligence

CVE-2021-47925: Tecnoteca CMDBuild stored XSS in card creation and file uploads

CVE-2021-47925 · Severity: medium · CVSS 6.4 · Published 2026-05-10

Executive brief

CMDBuild, an open-source asset management platform, is vulnerable to security flaws that allow users to inject malicious scripts into the system. An attacker with basic login access could upload harmful files or enter malicious text that triggers when other employees view asset records or file attachments. This could lead to unauthorized actions being performed in the context of other users' sessions, potentially compromising sensitive asset data or administrative controls.

Technical details

CMDBuild 3.3.2 contains multiple stored cross-site scripting (XSS) vulnerabilities due to improper neutralization of user-supplied input. Authenticated attackers can inject malicious payloads through 'Employee' card parameters (such as Code, Surname, or Name) or by uploading crafted SVG files as attachments in the classes endpoint. These scripts execute in the security context of any user who subsequently views the affected record or previews the attachment. The vulnerability is verified in version 3.3.2, and while newer versions like 4.2.0 are available, specific patch versions for the 3.x branch are not explicitly detailed in the advisory.

Affected products

  • Tecnoteca CMDBuild 3.3.2 and earlier

Timeline

  • 2021-11-15: disclosed: Initial discovery and exploit publication by Hosein Vita
  • 2026-05-10: advisory: NVD and VulnCheck advisory published

References