PT-2026-2946 · Unknown · Typesetter Cms
Snow1Nd
·
Published
2026-01-14
·
Updated
2026-01-14
·
CVE-2025-71166
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Typesetter CMS versions up to and including 5.1
Description
Typesetter CMS versions up to and including 5.1 have a reflected cross-site scripting (XSS) issue in the administrative interface, specifically within the Tools Status move message handling. The vulnerability occurs because a path parameter is reflected into the HTML output without proper output encoding in the
include/admin/Tools/Status.php file. An authenticated attacker can inject crafted input containing HTML or JavaScript, leading to arbitrary script execution within the browser session of an authenticated user.Recommendations
Versions prior to 5.1 are recommended.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typesetter Cms