PT-2025-20649 · Unknown · Lumi H5P-Nodejs-Library

Published

2025-05-11

·

Updated

2025-05-11

·

CVE-2025-47828

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lumi H5P-Nodejs-library versions prior to 9.3.3
Description The issue is related to the omission of a sanitizeHtml call for plain text strings. This could potentially lead to security issues, although specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations For versions prior to 9.3.3, update to version 9.3.3 or later to resolve the issue. As a temporary workaround, consider implementing additional sanitization for plain text strings to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-47828
GHSA-M7GM-V253-56HH

Affected Products

Lumi H5P-Nodejs-Library