Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25156

Опубликовано: 30 янв. 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be rendered in the user’s browser rather than downloaded. (The intended behavior was for only text/plain, application/pdf, image/gif, image/jpeg, and image/png to be delivered inline, though adding save=0 to the document URL could request inline delivery for any document.) This made users who clicked a document link vulnerable to cross-site scripting attacks. An uploaded HTML or SVG document would run in the viewer’s browser with access to their HotCRP credentials, and Javascript in that document could eventually make arbitrary calls to HotCRP’s API. Malicious documents could be uploaded to submission fields with “file upload” or “attachment” type, or as attachments to comments. PDF upload fields were not vulnerable. A search of documents uploaded to hotcrp.com found no evidence of exploi

EPSS

Процентиль: 9%
0.00033
Низкий

7.3 High

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 9%
0.00033
Низкий

7.3 High

CVSS3

Дефекты

CWE-79