Cross-Site Scripting Vulnerability in ZOO-Project Web Processing Service
CVE-2025-25190

5.5MEDIUM

Key Information:

Vendor
Zoo-project
Status
Zoo-project
Vendor
CVE Published:
10 February 2025

Summary

The ZOO-Project Web Processing Service (WPS) Server is affected by an XSS vulnerability due to improper sanitization of user input in the EchoProcess service. This vulnerability allows attackers to embed malicious JavaScript into SVG content processed by the server. When the service echoes this content back without adequate filtering, it executes arbitrary JavaScript in the user's browser, potentially leading to data theft or session hijacking. The impacted versions exist prior to commit 7a5ae1a, which addresses this issue by implementing proper input sanitation for various formats, including XML, JSON, and SVG.

Affected Version(s)

ZOO-Project < 7a5ae1a

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.