Cross-Site Scripting Vulnerability in Gstarsoft GstarCAD Software
CVE-2025-11137
What is CVE-2025-11137?
A cross-site scripting vulnerability has been identified in Gstarsoft GstarCAD, specifically affecting versions up to 9.4.0. This weakness arises from an insecure implementation within the File Renaming Handler component. Attackers can exploit this vulnerability remotely, potentially allowing them to execute arbitrary scripts in the context of the user's browser. Public disclosure of the exploit means that organizations should undertake immediate action by applying the recommended patch to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GstarCAD 9.0
GstarCAD 9.1
GstarCAD 9.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
