PT-2025-32432 · Unknown · Protected Total Webshield Extension

Khoadao-Fpt-Metrodata-Indonesia

·

Published

2025-08-09

·

Updated

2025-08-11

·

CVE-2025-8751

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Protected Total WebShield Extension versions up to 3.2.0
Description A vulnerability exists in the Block Page component of the software, allowing for cross site scripting through manipulation of the Category argument. The attack can be initiated remotely, but requires high complexity and is considered difficult to exploit. The exploit has been publicly disclosed, and the vendor was notified but did not respond.
Recommendations Update Protected Total WebShield Extension to a version later than 3.2.0.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8751

Affected Products

Protected Total Webshield Extension