Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

B1D0Ws

#48594of 53,632
5.1Total CVSS
Vulnerabilities · 1
PT-2025-22316
5.1
2025-05-20
Part-Db · Part-Db · CVE-2025-5007
**Name of the Vulnerable Software and Affected Versions** Part-DB versions up to 1.17.0 **Description** A vulnerability was found in the Profile Picture Feature of Part-DB, affecting the `handleUpload` function of the `AttachmentSubmitHandler.php` file. The manipulation of the `attachment` argument leads to cross-site scripting. The attack can be launched remotely. **Recommendations** For Part-DB versions up to 1.17.0, upgrade to version 1.17.1 to address this issue. As a temporary workaround, consider restricting the use of the `handleUpload` function of the `AttachmentSubmitHandler.php` file until the upgrade is applied.