Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-63588

Опубликовано: 06 нояб. 2025
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cmsimple-xh:cmsimple_xh:1.8.0:-:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.00074
Низкий

7.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
github
3 месяца назад

An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.

EPSS

Процентиль: 22%
0.00074
Низкий

7.1 High

CVSS3

Дефекты

CWE-79