Cross-Site Scripting Vulnerability in ZOO-Project Web Processing Service
CVE-2025-25190
5.5MEDIUM
Key Information:
- Vendor
- Zoo-project
- Status
- Zoo-project
- Vendor
- CVE Published:
- 10 February 2025
Summary
The ZOO-Project Web Processing Service (WPS) Server is affected by an XSS vulnerability due to improper sanitization of user input in the EchoProcess service. This vulnerability allows attackers to embed malicious JavaScript into SVG content processed by the server. When the service echoes this content back without adequate filtering, it executes arbitrary JavaScript in the user's browser, potentially leading to data theft or session hijacking. The impacted versions exist prior to commit 7a5ae1a, which addresses this issue by implementing proper input sanitation for various formats, including XML, JSON, and SVG.
Affected Version(s)
ZOO-Project < 7a5ae1a
References
CVSS V4
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved