Cross Site Scripting Vulnerability in vion707 DMadmin Backend Component
CVE-2025-14722
Key Information:
Badges
What is CVE-2025-14722?
A cross site scripting vulnerability exists in the Admin/Controller/AddonsController.class.php file of the vion707 DMadmin Backend component. This security flaw permits attackers to execute malicious scripts on the affected systems, which can be exploited remotely. Publicly disclosed, the vulnerability affects all versions up to 3403cafdb42537a648c30bf8cbc8148ec60437d1, and users are urged to remain vigilant as the vendor has not addressed the issue following initial notifications.
Affected Version(s)
DMadmin 3403cafdb42537a648c30bf8cbc8148ec60437d1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
