Cross-Site Scripting Vulnerability in ZOO-Project Web Processing Service
CVE-2025-25190
5.5MEDIUM
What is CVE-2025-25190?
The ZOO-Project Web Processing Service (WPS) Server is affected by an XSS vulnerability due to improper sanitization of user input in the EchoProcess service. This vulnerability allows attackers to embed malicious JavaScript into SVG content processed by the server. When the service echoes this content back without adequate filtering, it executes arbitrary JavaScript in the user's browser, potentially leading to data theft or session hijacking. The impacted versions exist prior to commit 7a5ae1a, which addresses this issue by implementing proper input sanitation for various formats, including XML, JSON, and SVG.
Affected Version(s)
ZOO-Project < 7a5ae1a