PT-2025-4558 · Unknown · Grandslambert Featured Page Widget
João Pedro S Alcântara
·
Published
2025-01-13
·
Updated
2025-01-13
·
CVE-2025-22569
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
The vulnerable software is grandslambert Featured Page Widget, with versions affected ranging from n/a to 2.2.
The vulnerability is an improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS), which allows for Reflected XSS attacks.
This vulnerability is identified by the CVE-2025-22569 designation.
There is no information provided about whether this vulnerability has a public exploit or if it has been exploited by attackers, nor is there information on how many Internet users could be affected by its exploitation.
The vulnerability can be exploited through the reflection of malicious scripts, allowing attackers to execute arbitrary code on the victim's browser.
#grandslambert #FeaturedPageWidget #CrossSiteScripting #XSS #ReflectedXSS #CVE202522569 #WebVulnerability #SecurityVulnerability
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grandslambert Featured Page Widget