PT-2026-46209 · Gigtodoscript · Gigtodo

M0Ze

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2019-25739

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create proposal endpoint that execute when administrators or other users view the stored proposal, enabling cookie theft and malicious redirects.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25739

Affected Products

Gigtodo