PT-2025-44444 · Zucchetti · Zucchetti Ad Hoc Revolution

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2025-52179

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zucchetti Ad Hoc Revolution versions 4.1 and earlier
Description A cross-site scripting (XSS) issue exists in Zucchetti Ad Hoc Revolution. This allows attackers to inject arbitrary JavaScript code. The issue is present in the /ahrw/jsp/gsfr feditorHTML.jsp API endpoint through the pHtmlSource parameter. The vulnerability does not require authentication.
Recommendations Versions prior to 4.1 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52179

Affected Products

Zucchetti Ad Hoc Revolution