PT-2025-10640 · Tianti · Tianti

Kagty1O

·

Published

2025-03-10

·

Updated

2025-06-23

·

CVE-2025-25908

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions tianti version 2.3
Description A stored cross-site scripting issue allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the coverImageURL parameter at the "/article/ajax/save" API endpoint.
Recommendations For version 2.3, avoid using the coverImageURL parameter in the affected API endpoint until the issue is resolved. Consider implementing input validation and sanitization for the coverImageURL parameter to prevent malicious payload injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-25908

Affected Products

Tianti