Cross-Site Scripting Vulnerability in aitangbao springboot-manager by aitangbao
CVE-2025-2206
Key Information:
- Vendor
Aitangbao
- Status
- Vendor
- CVE Published:
- 11 March 2025
Badges
What is CVE-2025-2206?
A cross-site scripting (XSS) vulnerability has been discovered in aitangbao springboot-manager 3.0 that could allow an attacker to manipulate user input through the argument name in the /sys/permission file. This flaw enables attackers to execute malicious scripts in the context of the affected user's session, facilitating unauthorized access and data manipulation. The vulnerability can be exploited remotely, posing a significant risk to users of the affected product. The vendor has been informed of this security issue, but no response was received regarding a mitigation strategy.
Affected Version(s)
springboot-manager 3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved