Cross-Site Scripting Vulnerability in Paraşüt Software by Paraşüt
CVE-2025-0420

4.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-0420?

The vulnerability in Paraşüt Software allows attackers to exploit Cross-Site Scripting (XSS) by improperly neutralizing user input during web page generation. This flaw affects versions from 0.0.0.65efa44e to 20250204, enabling malicious actors to execute arbitrary scripts in the context of users’ browsers. As a result, sensitive information could be compromised and users may be redirected to harmful sites.

Affected Version(s)

Paraşüt 0.0.0.65efa44e <= 20250204

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Berat ARSLAN
.
CVE-2025-0420 : Cross-Site Scripting Vulnerability in Paraşüt Software by Paraşüt