PT-2025-54299 · Shuttlethemes · Shuttlethemes Shuttle

Peter Thaleikis

·

Publicado

2025-12-31

·

Atualizado

2025-12-31

·

CVE-2025-62137

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Shuttlethemes Shuttle versions through 1.5.0
Description The Shuttlethemes Shuttle software contains a flaw related to improper input handling during web page generation, which allows for Stored Cross-site Scripting (XSS). This can potentially allow an attacker to inject malicious scripts into web pages viewed by other users. The affected component is susceptible to exploitation through crafted input.
Recommendations Update Shuttlethemes Shuttle to a version later than 1.5.0.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-62137

Produtos afetados

Shuttlethemes Shuttle