PT-2025-14753 · Unknown · Labib Ahmed Team Builder

Abdi Pranata

·

Published

2025-04-03

·

Updated

2025-04-05

·

CVE-2025-31907

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Labib Ahmed Team Builder versions n/a through 1.3
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as 'Cross-site Scripting', which allows Reflected XSS. This means that an attacker can inject malicious scripts into the website, potentially stealing user data or taking control of user sessions.
Recommendations For versions n/a through 1.3, consider disabling any features that allow user input to be reflected in the web page until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using user-supplied input in API endpoints, such as /api/v1/login, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-31907

Affected Products

Labib Ahmed Team Builder