Cross Site Scripting Vulnerability in aitangbao Springboot-Manager Product
CVE-2025-2210
What is CVE-2025-2210?
A cross site scripting vulnerability has been identified in aitangbao's springboot-manager version 3.0. This issue arises from the manipulation of the 'name' argument within the file path /sysJob/add, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, compromising user sessions and leading to unauthorized actions. The details surrounding this exploit have been made publicly available, and the vendor did not respond to early disclosure attempts, increasing the urgency for users to assess their risk exposure and apply any available mitigations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
springboot-manager 3.0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
