Cross-Site Scripting Vulnerability in PhiloPress BP Email Assign Templates
CVE-2025-24631
7.1HIGH
Summary
PhiloPress BP Email Assign Templates has a vulnerability due to improper neutralization of input during web page generation, allowing for reflected Cross-Site Scripting (XSS) attacks. This vulnerability can potentially allow an attacker to inject malicious scripts into webpages viewed by other users, thereby compromising user data and compromising web application integrity. The affected versions range from n/a through 1.5, highlighting the importance of ensuring that users operate the latest, patched versions to mitigate risks.
Affected Version(s)
BP Email Assign Templates <= 1.5
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
0xd4rk5id3 (Patchstack Alliance)