PT-2025-32385 · Ehcp · Ehcp

Published

2025-08-08

·

Updated

2025-08-08

·

CVE-2025-50927

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions EHCP version 20.04.1.b
Description A reflected cross-site scripting (XSS) vulnerability exists in the List All FTP User Function. Authenticated attackers can execute arbitrary JavaScript by injecting a crafted payload into the ftpusername parameter.
Recommendations As a temporary workaround, sanitize the ftpusername parameter to prevent the injection of malicious scripts.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-50927

Affected Products

Ehcp