CVE-2025-60445: XSS
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the dayrui/Fcms/Library/Upload.php component, allowing attackers to inject malicious JavaScript code that executes when the uploaded file is viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60445?
CVE-2025-60445 is classified as a high-severity stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-60445?
To fix CVE-2025-60445, ensure proper validation and sanitization of uploaded SVG files in the affected component.
Which versions of XunRuiCMS are affected by CVE-2025-60445?
CVE-2025-60445 specifically affects XunRuiCMS version 4.7.1.
What kind of attacks can CVE-2025-60445 enable?
CVE-2025-60445 can enable attackers to perform stored XSS attacks by injecting malicious JavaScript into the application.
Where is the vulnerable code in CVE-2025-60445 located?
The vulnerable code for CVE-2025-60445 is located in the dayrui/Fcms/Library/Upload.php component of XunRuiCMS.