PT-2025-54305 · Unknown · Ruhul Amin Content Fetcher

Jitlada

·

Published

2025-12-31

·

Updated

2026-01-01

·

CVE-2025-49358

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ruhul Amin Content Fetcher versions through 1.1
Description The Ruhul Amin Content Fetcher software contains a flaw related to improper input handling during web page generation, specifically a DOM-Based Cross-Site Scripting (XSS) issue. This allows for the potential execution of malicious scripts within the application. The vulnerability exists due to insufficient sanitization of user-supplied input before it is incorporated into the web page's Document Object Model (DOM). This could allow an attacker to inject arbitrary HTML or JavaScript code into the page, which would then be executed by the victim's browser. The affected API endpoints and vulnerable parameters were not specified.
Recommendations Update Ruhul Amin Content Fetcher to a version beyond 1.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-49358

Affected Products

Ruhul Amin Content Fetcher