Executive brief
CMDBuild, an open-source asset management platform, is vulnerable to security flaws that allow users to inject malicious scripts into the system. An attacker with basic login access could upload harmful files or enter malicious text that triggers when other employees view asset records or file attachments. This could lead to unauthorized actions being performed in the context of other users' sessions, potentially compromising sensitive asset data or administrative controls.
Technical details
CMDBuild 3.3.2 contains multiple stored cross-site scripting (XSS) vulnerabilities due to improper neutralization of user-supplied input. Authenticated attackers can inject malicious payloads through 'Employee' card parameters (such as Code, Surname, or Name) or by uploading crafted SVG files as attachments in the classes endpoint. These scripts execute in the security context of any user who subsequently views the affected record or previews the attachment. The vulnerability is verified in version 3.3.2, and while newer versions like 4.2.0 are available, specific patch versions for the 3.x branch are not explicitly detailed in the advisory.
Affected products
- Tecnoteca CMDBuild 3.3.2 and earlier
Timeline
- 2021-11-15: disclosed: Initial discovery and exploit publication by Hosein Vita
- 2026-05-10: advisory: NVD and VulnCheck advisory published