CVE-2025-45313: XSS
Published Aug 13, 2025
·Updated
A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter.
Affected Software
2 affected components
HortusFox hortusfox-web
HortusFox hortusfox=4.4
Event History
Aug 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to get a user to interact with a crafted payload submitted through the title parameter on the /tasks endpoint. No attacker privileges are required, but user interaction is required.
2
What is the likely impact if exploitation succeeds?
The attacker can execute arbitrary JavaScript in the affected user's browser context. The CVSS vector indicates potential low-impact confidentiality and integrity effects, with no availability impact identified.