Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-10485

Опубликовано: 15 сент. 2025
Источник: nvd
CVSS3: 4.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

EPSS

Процентиль: 18%
0.00056
Низкий

4.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.3
github
5 месяцев назад

A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

EPSS

Процентиль: 18%
0.00056
Низкий

4.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-79