Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-35996

Опубликовано: 01 мая 2025
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.

EPSS

Процентиль: 23%
0.00077
Низкий

9 Critical

CVSS3

Дефекты

CWE-97

Связанные уязвимости

CVSS3: 9
github
9 месяцев назад

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.

EPSS

Процентиль: 23%
0.00077
Низкий

9 Critical

CVSS3

Дефекты

CWE-97