PT-2025-7592 · Phpress · Ppress
Coleak2021
·
Published
2025-02-20
·
Updated
2025-02-20
·
CVE-2025-25973
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ppress version 0.0.9
Description
A stored Cross-Site Scripting vulnerability in the "related recommendations" feature allows a remote attacker to execute arbitrary code via a crafted script to the
article.title, article.category, and article.tags parameters.Recommendations
For Ppress version 0.0.9, as a temporary workaround, consider disabling the "related recommendations" feature until a patch is available. Restrict access to the
article.title, article.category, and article.tags parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ppress