Persistent Cross-Site Scripting Vulnerability in GigToDo by GigToDo Scripts
CVE-2019-25739
Key Information:
- Vendor
Gigtodoscript
- Status
- Vendor
- CVE Published:
- 4 June 2026
Badges
What is CVE-2019-25739?
The GigToDo 1.3 platform has a persistent cross-site scripting vulnerability that permits authenticated users to inject harmful JavaScript and HTML content via the proposal description field. This vulnerability affects the create_proposal endpoint, which allows attackers to craft targeted XSS payloads. When administrators or other users access the stored proposals, these malicious scripts can execute, leading to serious security risks such as cookie theft and unwanted redirects to dubious web pages.
Affected Version(s)
GigToDo 0 <= 1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
