Cross-Site Scripting Vulnerability in aitangbao Springboot-Manager by aitangbao
CVE-2025-2208
What is CVE-2025-2208?
A cross-site scripting vulnerability has been identified in the aitangbao Springboot-Manager 3.0. The flaw lies in the Filename Handler component, specifically in the handling of file uploads. Manipulation of the 'name' argument in the /sysFiles/upload file can lead to the execution of malicious scripts in the context of a user's browser. This vulnerability allows attackers to potentially perform unauthorized actions or retrieve sensitive information from users' sessions. The issue has been publicly disclosed, indicating that exploitation could be imminent, as the vendor has yet to respond to alert notifications regarding the flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
springboot-manager 3.0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
