PT-2025-52203 · Boldgrid · Boldgrid Sprout Clients

Nguyen Xuan Chien

·

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2025-66118

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions BoldGrid Sprout Clients versions through 3.2.1
Description A flaw exists in BoldGrid Sprout Clients that allows for Reflected Cross-site Scripting (XSS). This issue arises from improper input validation during web page generation. The vulnerability affects the sprout-clients component.
Recommendations Update BoldGrid Sprout Clients to a version later than 3.2.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66118

Affected Products

Boldgrid Sprout Clients