Cross-Site Scripting in Yi-ge Get-Header-IP PHP Application
CVE-2025-10944
5.1MEDIUM
What is CVE-2025-10944?
A vulnerability has been discovered in the Yi-ge Get-Header-IP application affecting the ip function within ip.php. This security flaw enables an attacker to manipulate the argument callback, potentially leading to cross-site scripting (XSS) attacks. Such attacks may be carried out remotely, posing significant risks to users. The affected product follows a rolling release model, which complicates the identification of specific impacted versions. Despite notifying the vendor regarding this issue, no response was received.
Affected Version(s)
get-header-ip 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15