PT-2025-48370 · Xmall · Xmall

Ylchen-007

·

Published

2025-11-29

·

Updated

2025-11-29

·

CVE-2025-65540

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions xmall version 1.1
Description Multiple Cross-Site Scripting (XSS) issues are present due to improper handling of user-supplied data. User input fields, including username and description, are directly rendered into HTML without appropriate sanitization or encoding. This allows attackers to inject and execute malicious scripts.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-65540

Affected Products

Xmall