PT-2025-27208 · Hidepost · Hidepost

Nguyen Xuan Chien

·

Published

2025-06-27

·

Updated

2025-06-27

·

CVE-2025-53310

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: HidePost versions prior to 2.3.8
Description: A Cross-Site Request Forgery (CSRF) issue in HidePost allows for Reflected XSS. This means an attacker could potentially trick a user into performing unintended actions on the web application.
Recommendations: For versions prior to 2.3.8, update to a version that includes a fix for this issue. As a temporary workaround, consider implementing additional CSRF protection measures, such as token-based validation, to minimize the risk of exploitation. Restrict access to sensitive operations that could be manipulated through Reflected XSS attacks until the issue is resolved.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-53310

Affected Products

Hidepost