First published: Mon May 05 2025(Updated: )
A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/user/edit.do of the component Edit User Page. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mrcms |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4292 is classified as a problematic vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2025-4292, update MRCMS to the latest version that addresses this vulnerability.
CVE-2025-4292 affects the Edit User Page functionality of the /admin/user/edit.do component.
The vulnerability allows for cross-site scripting (XSS) attacks through manipulation of the Username argument.
CVE-2025-4292 affects MRCMS version 3.1.3.