Cross-Site Scripting Vulnerability in iteaj iboot File Upload Component
CVE-2025-3326
5.1MEDIUM
Key Information:
- Vendor
Iteaj
- Status
- Vendor
- CVE Published:
- 7 April 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-3326?
A vulnerability exists in the iteaj iboot File Upload component, specifically within the file path /common/upload, that allows the manipulation of arguments related to file uploads. This vulnerability can result in cross-site scripting (XSS) attacks, potentially allowing an attacker to execute arbitrary scripts in the context of a user’s browser. Because the exploit is publicly disclosed, it is crucial for users of affected versions to implement necessary security measures to safeguard against remote attacks.
Affected Version(s)
iboot 物联网网关 1.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.