PT-2025-33675 · Genealogy · Genealogy

Eternalvalhalla

·

Published

2025-08-18

·

Updated

2025-08-18

·

CVE-2025-55288

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Genealogy versions prior to 4.4.0
Description: Genealogy is a family tree PHP application susceptible to an authenticated reflected cross-site scripting (XSS) issue. An attacker with valid credentials can execute arbitrary JavaScript code within another user's session, potentially leading to session hijacking, data theft, and user interface manipulation.
Recommendations: Update to version 4.4.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55288
GHSA-3H8X-G9XJ-RHWG

Affected Products

Genealogy