Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-11146

Опубликовано: 29 сент. 2025
Источник: debian
EPSS Низкий

Описание

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apt-cacher-ngfixed3.7.5-1package
apt-cacher-ngno-dsabookwormpackage
apt-cacher-ngpostponedbullseyepackage

Примечания

  • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-apt-cacher-ng

  • https://salsa.debian.org/blade/apt-cacher-ng/-/commit/b03d9a3ab326aad2538f42d2831b3114b830912b (upstream/3.7.5)

EPSS

Процентиль: 16%
0.00052
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.

CVSS3: 5.4
nvd
4 месяца назад

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.

CVSS3: 5.4
github
4 месяца назад

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.

EPSS

Процентиль: 16%
0.00052
Низкий