PT-2025-29418 · Unknown · Bigotry Onebase
Jiashenghe
·
Publicado
2025-07-14
·
Atualizado
2025-07-14
·
CVE-2025-7569
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Bigotry OneBase versions through 1.3.6
Description:
A flaw exists in Bigotry OneBase that allows for cross site scripting. The issue is located in the
parse args function within the /tpl/think exception.tpl file. Manipulation of the args argument can trigger the flaw. The attack can be initiated remotely. The details of the exploit have been publicly disclosed.Recommendations:
Versions prior to 1.3.6 are affected.
As a temporary workaround, consider restricting access to the
/tpl/think exception.tpl file until a patch is available.
Avoid using the args argument in the parse args function until the issue is resolved.Exploit
Correção
Code Injection
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bigotry Onebase