Cross Site Scripting Vulnerability in baowzh hfly Component
CVE-2025-14519
Key Information:
Badges
What is CVE-2025-14519?
A security flaw has been identified in the baowzh hfly up to version 638ff9abe9078bc977c132b37acbe1900b63491c, specifically within the advtext Module's handling of the /admin/index.php/advtext/add file. This vulnerability allows for the manipulation of the component, which can lead to cross site scripting (XSS) attacks that are executable remotely. The exploit for this vulnerability has been made publicly accessible, indicating an urgent need for users to address and mitigate the risk. The vendor was unresponsive to early notifications regarding the vulnerability.
Affected Version(s)
hfly 638ff9abe9078bc977c132b37acbe1900b63491c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
