Cross-Site Scripting Vulnerability in Hortusfox-Web by Daniel Brendel
CVE-2025-45316

6.1MEDIUM

Key Information:

Vendor
CVE Published:
13 August 2025

What is CVE-2025-45316?

A cross-site scripting (XSS) vulnerability exists in the TextBlockModule.php component of hortusfox-web v4.4. This flaw allows attackers to inject malicious scripts or HTML by manipulating the name parameter, potentially compromising the security of users' interactions on affected applications. Attackers can exploit this vulnerability to execute arbitrary code, leading to unauthorized data access or site defacement.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.