PT-2025-46677 · Rarlab · Winrar
Published
2025-11-12
·
Updated
2025-12-31
·
CVE-2025-52331
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WinRAR version 7.11
Description
A cross-site scripting (XSS) issue exists in the generate report functionality. This allows attackers to potentially disclose user information, including the computer username, generated report directory, and IP address. The issue occurs because the generate report command includes archived file names without validation in the HTML report, enabling the injection of potentially malicious HTML tags. User interaction is required, specifically using the "generate report" functionality and opening the report.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winrar