Cross-Site Scripting Vulnerability in pojoin h3blog Version 1.0
CVE-2025-13181
Key Information:
Badges
What is CVE-2025-13181?
A cross-site scripting vulnerability has been identified in pojoin h3blog version 1.0. This vulnerability resides in the handling of the 'Name' argument within the /admin/cms/material/add file. By exploiting this flaw, an attacker may execute arbitrary scripts in the user's browser, leading to potential data theft, session hijacking, or other malicious actions. The vulnerability is remotely exploitable and has been publicly disclosed, making it crucial for users to assess their exposure and implement necessary mitigations.
Affected Version(s)
h3blog 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
