First published: Fri Jan 31 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bryan Shanaver @ fiftyandfifty.org CloudFlare(R) Cache Purge allows Reflected XSS. This issue affects CloudFlare(R) Cache Purge: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudflare Cache Purge | >=n/a<=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22332 has a medium severity rating due to its potential for reflected XSS attacks.
To fix CVE-2025-22332, update CloudFlare Cache Purge to version 1.3 or later, where the vulnerability is patched.
CVE-2025-22332 affects CloudFlare Cache Purge versions from n/a to 1.2.
CVE-2025-22332 is classified as a Cross-site Scripting (XSS) vulnerability.
Yes, CVE-2025-22332 can be exploited remotely through crafted web requests.