CVE-2025-25957: XSS
Published Feb 20, 2025
·Updated
Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.
Affected Software
2 affected components
Xunruicms Xunruicms<4.6.3
Xunruicms Xunruicms<=4.6.3
Event History
Feb 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25957?
CVE-2025-25957 has a high severity due to its potential for privilege escalation via Cross Site Scripting.
2
How do I fix CVE-2025-25957?
To fix CVE-2025-25957, update Xunruicms to version 4.6.4 or later.
3
What are the potential impacts of CVE-2025-25957?
The potential impacts of CVE-2025-25957 include unauthorized access and control over the affected application.
4
Which versions of Xunruicms are affected by CVE-2025-25957?
Xunruicms versions 4.6.3 and earlier are affected by CVE-2025-25957.
5
Who can exploit CVE-2025-25957?
CVE-2025-25957 can be exploited by remote attackers with the ability to inject crafted scripts.