PT-2025-37364 · Unmark · Unmark
Cdevroe
·
Published
2025-09-13
·
Updated
2025-09-13
·
CVE-2025-10332
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
cdevroe unmark versions up to 1.9.3
Description
A cross-site scripting issue exists due to manipulation of the
Title argument. This impacts an unknown function within the application/views/marks/info.php file. The attack can be carried out remotely, and an exploit has been publicly released. The vendor was notified but did not respond.Recommendations
Versions prior to 1.9.3: Address the cross-site scripting issue by sanitizing the
Title argument before using it in the application/views/marks/info.php file.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unmark