Cross Site Scripting Vulnerability in aitangbao Springboot-Manager Product
CVE-2025-2210

4.8MEDIUM

Key Information:

Vendor
Aitangbao
Vendor
CVE Published:
11 March 2025

Badges

👾 Exploit Exists

Summary

A cross site scripting vulnerability has been identified in aitangbao's springboot-manager version 3.0. This issue arises from the manipulation of the 'name' argument within the file path /sysJob/add, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, compromising user sessions and leading to unauthorized actions. The details surrounding this exploit have been made publicly available, and the vendor did not respond to early disclosure attempts, increasing the urgency for users to assess their risk exposure and apply any available mitigations.

Affected Version(s)

springboot-manager 3.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

uglory (VulDB User)
.
CVE-2025-2210 : Cross Site Scripting Vulnerability in aitangbao Springboot-Manager Product | SecurityVulnerability.io