PT-2025-54305 · Unknown · Ruhul Amin Content Fetcher
Jitlada
·
Published
2025-12-31
·
Updated
2026-01-01
·
CVE-2025-49358
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Ruhul Amin Content Fetcher versions through 1.1
Description
The Ruhul Amin Content Fetcher software contains a flaw related to improper input handling during web page generation, specifically a DOM-Based Cross-Site Scripting (XSS) issue. This allows for the potential execution of malicious scripts within the application. The vulnerability exists due to insufficient sanitization of user-supplied input before it is incorporated into the web page's Document Object Model (DOM). This could allow an attacker to inject arbitrary HTML or JavaScript code into the page, which would then be executed by the victim's browser. The affected API endpoints and vulnerable parameters were not specified.
Recommendations
Update Ruhul Amin Content Fetcher to a version beyond 1.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruhul Amin Content Fetcher