PT-2026-2944 · Unknown · Typesetter Cms
Snow1Nd
·
Published
2026-01-14
·
Updated
2026-01-21
·
CVE-2025-71164
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Typesetter CMS versions up to and including 5.1
Description
Typesetter CMS versions up to and including 5.1 have a reflected cross-site scripting (XSS) issue in the Editing component. The
images parameter, submitted as images[] in a POST request, is reflected into an HTML href attribute without proper output encoding in include/tool/Editing.php. An authenticated attacker with editing privileges can use a JavaScript pseudo-protocol to execute arbitrary JavaScript in the victim’s browser session.Recommendations
Versions prior to 5.1 should be used.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typesetter Cms