PT-2025-54441 · Unknown · Zhinatwitterwidget

João Pedro S Alcântara

+1

·

Published

2025-12-31

·

Updated

2025-12-31

·

CVE-2025-23719

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ZhinaTwitterWidget versions through 1.0
Description The software contains a flaw related to improper input handling during web page generation, specifically a Reflected Cross-site Scripting (XSS) issue. This allows for the injection of malicious scripts through web pages. The vulnerable component is susceptible to attacks where an attacker can inject arbitrary web scripts. The affected API endpoint is not specified. The vulnerable parameter is not specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-23719

Affected Products

Zhinatwitterwidget