PT-2026-2945 · Unknown · Typesetter Cms
Snow1Nd
·
Publicado
2026-01-14
·
Atualizado
2026-01-15
·
CVE-2025-71165
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Typesetter CMS versions up to and including 5.1
Description
Typesetter CMS versions up to and including 5.1 have a reflected cross-site scripting (XSS) issue in the administrative interface within the Tools Status functionality. The path parameter is reflected into the HTML response without proper output encoding in the
include/admin/Tools/Status.php file. An authenticated attacker can inject crafted input containing HTML or JavaScript, leading to arbitrary script execution within the context of an authenticated user’s browser session.Recommendations
Versions prior to 5.1 should be used.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Typesetter Cms