PT-2025-31873 · Exrick · Exrick Xboot

Zast.Ai

·

Published

2025-08-04

·

Updated

2025-08-04

·

CVE-2025-8528

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Exrick xboot versions through 3.3.4
Description A problematic issue has been identified in Exrick xboot. The issue resides in an unknown function within the /xboot/permission/getMenuList file. Manipulation of this function results in the storage of sensitive information in cleartext within a cookie. The attack can be executed remotely and is considered to have relatively high complexity, making exploitation difficult. The exploit has been publicly disclosed and may be utilized.
Recommendations Versions prior to 3.3.5: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-8528

Affected Products

Exrick Xboot