PT-2025-10640 · Tianti · Tianti

Kagty1O

·

Publicado

2025-03-10

·

Atualizado

2025-06-23

·

CVE-2025-25908

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions tianti version 2.3
Description A stored cross-site scripting issue allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the coverImageURL parameter at the "/article/ajax/save" API endpoint.
Recommendations For version 2.3, avoid using the coverImageURL parameter in the affected API endpoint until the issue is resolved. Consider implementing input validation and sanitization for the coverImageURL parameter to prevent malicious payload injection.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-25908

Produtos afetados

Tianti