PT-2025-46200 · Unknown · Changedetection.Io

Edoardottt

·

Published

2025-11-10

·

Updated

2026-02-25

·

CVE-2025-62780

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions changedetection.io versions prior to 0.50.34
Description A Stored Cross Site Scripting issue exists in changedetection.io’s Watch update API due to inadequate security checks. An attacker can insert a new watch with a URL pointing to a web page, then modify the URL to include a JavaScript payload. Alternatively, an attacker can replace the URL in an existing watch with a JavaScript payload. When a user previews the malicious link, the JavaScript code is executed. This impacts the application's ability to securely handle user-provided URLs.
Recommendations Update to version 0.50.34 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-62780
GHSA-4C3J-3H7V-22Q9
PYSEC-2025-91

Affected Products

Changedetection.Io