CVE-2025-44115: XSS
A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44115?
CVE-2025-44115 is classified as a cross-site scripting vulnerability, which can lead to significant security risks.
How do I fix CVE-2025-44115?
To fix CVE-2025-44115, update Cotonti Siena to the latest version or patch the vulnerable code to properly sanitize user input.
What impact does CVE-2025-44115 have on my application?
CVE-2025-44115 allows attackers to inject malicious scripts into web pages viewed by users, compromising their data and introducing potential harm.
Is CVE-2025-44115 easy to exploit?
Yes, CVE-2025-44115 can be easily exploited by attackers familiar with cross-site scripting techniques.
Which software versions are affected by CVE-2025-44115?
CVE-2025-44115 specifically affects Cotonti Siena version 0.9.25.