CVE-2025-65233: XSS
Published Dec 17, 2025
·Updated
Reflected cross-site scripting (XSS) in SLiMS (slims9bulian) before 9.6.0 via improper handling of $SERVER['PHPSELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.
Affected Software
2 affected components
Slims SLIMS<9.6.0
Slims Project Slims<9.6.0
Event History
Dec 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65233?
CVE-2025-65233 has a severity rating that indicates a high risk due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2025-65233?
To fix CVE-2025-65233, upgrade SLiMS to version 9.6.0 or later, which addresses the vulnerability.
3
Who is affected by CVE-2025-65233?
Users of SLiMS versions prior to 9.6.0 are affected by CVE-2025-65233.
4
What type of vulnerability is CVE-2025-65233?
CVE-2025-65233 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-65233 allow execution of arbitrary code?
Yes, CVE-2025-65233 can allow remote attackers to execute arbitrary JavaScript in the victim's browser.