PT-2026-6740 · Thrsrossi · Millhouse-Project

Cakes

·

Published

2026-02-06

·

Updated

2026-02-06

·

CVE-2019-25301

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Millhouse-Project version 1.414
Description A persistent cross-site scripting issue exists in the comment submission functionality. This allows attackers to inject malicious scripts by posting comments with embedded JavaScript through the 'add comment sql.php' endpoint using the content parameter, leading to the execution of arbitrary scripts in the browsers of users who view the comments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25301

Affected Products

Millhouse-Project