Cross Site Scripting Vulnerability in aitangbao Springboot-Manager Product
CVE-2025-2210
4.8MEDIUM
Summary
A cross site scripting vulnerability has been identified in aitangbao's springboot-manager version 3.0. This issue arises from the manipulation of the 'name' argument within the file path /sysJob/add, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, compromising user sessions and leading to unauthorized actions. The details surrounding this exploit have been made publicly available, and the vendor did not respond to early disclosure attempts, increasing the urgency for users to assess their risk exposure and apply any available mitigations.
Affected Version(s)
springboot-manager 3.0
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
uglory (VulDB User)