CVE-2025-63588: XSS
An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63588?
CVE-2025-63588 is classified as a high severity vulnerability due to its potential for unauthenticated remote code execution via reflected cross-site scripting.
How do I fix CVE-2025-63588?
To fix CVE-2025-63588, upgrade to the patched version of CMSimpleXH that addresses the reflected XSS vulnerability.
Who is affected by CVE-2025-63588?
CVE-2025-63588 affects users of CMSimpleXH version 1.8.0 and earlier who use the vulnerable query handling feature.
What type of attack is CVE-2025-63588 associated with?
CVE-2025-63588 is associated with reflected cross-site scripting attacks, allowing attackers to inject malicious JavaScript.
What could be the impact of exploiting CVE-2025-63588?
Exploiting CVE-2025-63588 could lead to the theft of sensitive information from users, including credentials and personal data.