CVE-2025-45314: XSS
Published Aug 13, 2025
·Updated
A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function.
Affected Software
2 affected components
HortusFox hortusfox-web
HortusFox HortusFox=4.4
Event History
Aug 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Does exploitation require an authenticated account?
No privileges are required according to the CVSS vector. Exploitation does require a user to interact with attacker-controlled content.
2
What is the expected impact if exploitation succeeds?
An attacker can execute arbitrary JavaScript in the affected user's browser context. The CVSS assessment indicates low confidentiality and integrity impact, with no availability impact.