Roothub · Roothub · CVE-2025-8211
**Name of the Vulnerable Software and Affected Versions**
Roothub versions up to 2.6
**Description**
A vulnerability exists in Roothub that allows for cross site scripting. The issue is located in the `Edit` function within the `src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java` file. The attack can be launched remotely, and details of the exploit have been publicly disclosed.
**Recommendations**
Roothub versions prior to 2.7: Address the cross site scripting issue in the `Edit` function of the `src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java` file.