PT-2025-38622 · Unknown · Paracrawl Keops V2

Shaunak Chatterjee

·

Published

2025-09-19

·

Updated

2025-09-20

·

CVE-2025-56762

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Paracrawl KeOPs v2 (affected versions not specified)
Description Paracrawl KeOPs v2 is susceptible to a Cross-Site Scripting (XSS) issue in the error.php file. This allows for the injection of malicious scripts into the application, potentially compromising user data or system integrity. The vulnerability resides in the handling of input within the error.php file, enabling attackers to execute arbitrary JavaScript code in the context of a user's browser. The error.php file is the entry point for the XSS attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-56762

Affected Products

Paracrawl Keops V2