PT-2026-7907 · Unknown · Lty628 Aidigu

Published

2026-02-12

·

Updated

2026-02-12

·

CVE-2025-70845

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions lty628 aidigu version 1.9.1
Description The software contains a Cross Site Scripting (XSS) issue in the '/setting/' page. The "intro" field is not properly sanitized or escaped, allowing for potential exploitation. The vulnerable parameter is intro.
Recommendations Ensure proper sanitization and escaping of the "intro" field in the '/setting/' page.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-70845

Affected Products

Lty628 Aidigu