PT-2025-32001 · Unknown +3 · Modsecurity +3

Orangetw

·

Published

2025-08-05

·

Updated

2025-08-06

·

CVE-2025-54571

CVSS v4.0
6.9
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Name of the Vulnerable Software and Affected Versions:

ModSecurity versions 2.9.11 and below

Description:

ModSecurity is a web application firewall engine for Apache, IIS, and Nginx. An attacker can override the HTTP response’s Content-Type, potentially leading to issues such as cross-site scripting (XSS) and arbitrary script source code disclosure.

Recommendations:

Update to version 2.9.12 or later.

Exploit

Fix

Unchecked Return Value

Weakness Enumeration

Related Identifiers

CVE-2025-54571
GHSA-CG44-9M43-3F9V

Affected Products

Apache
Iis
Modsecurity
Nginx