PT-2025-4785 · Caido · Caido

0Xwr41Th

·

Published

2025-01-17

·

Updated

2025-01-17

·

CVE-2025-23039

CVSS v3.1

5.2

Medium

VectorAV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Caido version 0.45.0
Description A Cross-Site Scripting (XSS) issue was identified in Caido due to improper sanitization in the URL decoding tooltip of HTTP request and response editors. This could allow an attacker to execute arbitrary scripts, potentially leading to the theft of sensitive information.
Recommendations For version 0.45.0, upgrade to version 0.45.1 to address the issue. At the moment, there is no information about other mitigation measures for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-23039
GHSA-3MFW-FHFP-MGRV

Affected Products

Caido