PT-2025-33674 · Genealogy · Genealogy

Eternalvalhalla

·

Published

2025-08-18

·

Updated

2025-08-18

·

CVE-2025-55287

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Genealogy versions prior to 4.4.0
Description: Genealogy is a family tree PHP application susceptible to an authenticated stored cross-site scripting (XSS) issue. Attackers with valid credentials can execute arbitrary JavaScript code within another user's session, potentially leading to session hijacking, data theft, and UI manipulation.
Recommendations: Update to version 4.4.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55287
GHSA-J457-9M86-6Q5R

Affected Products

Genealogy