PT-2025-48371 · Krpano · Krpano

Published

2025-11-29

·

Updated

2025-11-29

·

CVE-2025-65892

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions krpano versions prior to 1.23.2
Description A reflected Cross-Site Scripting (rXSS) issue exists in krpano. A remote, unauthenticated attacker can execute arbitrary JavaScript in a victim’s browser through a specially crafted URL. The issue involves the
passQueryParameters
function when the
xml
parameter is enabled. The
xml
parameter is a vulnerable parameter.
Recommendations Update to version 1.23.2 or later.

Related Identifiers

CVE-2025-65892

Affected Products

Krpano