CVE-2025-45315: XSS
Published Aug 13, 2025
·Updated
A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.
Affected Software
2 affected components
HortusFox hortusfox-web
HortusFox HortusFox=4.4
Event History
Aug 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45315?
CVE-2025-45315 is considered a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-45315?
To fix CVE-2025-45315, sanitize and validate all user inputs, especially the email parameter, to prevent script injection.
3
What systems are affected by CVE-2025-45315?
CVE-2025-45315 affects HortusFox web application version 4.4.
4
Can CVE-2025-45315 be exploited remotely?
Yes, CVE-2025-45315 can be exploited remotely by attackers injecting malicious scripts into the email parameter.
5
What types of attacks can result from CVE-2025-45315?
CVE-2025-45315 can lead to various attacks including session hijacking and phishing through malicious JavaScript execution.