Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-61431

Опубликовано: 04 нояб. 2025
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the pHtmlSource parameter. A vendor fix was released on 2025-06-18.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zucchetti:infinity_zmaintenance:*:*:*:*:*:*:*:*
Версия до 4.1 (включая)
cpe:2.3:a:zucchetti:infinity_zucchetti:*:*:*:*:*:*:*:*
Версия до 4.1 (включая)

EPSS

Процентиль: 12%
0.00039
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
3 месяца назад

A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the pHtmlSource parameter. A vendor fix was released on 2025-06-18.

EPSS

Процентиль: 12%
0.00039
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79