Cross-Site Scripting Vulnerability in Rarlab WinRAR Product
CVE-2025-52331

6.1MEDIUM

Key Information:

Vendor

Rarlab

Status
Vendor
CVE Published:
12 November 2025

What is CVE-2025-52331?

A cross-site scripting vulnerability exists in the generate report functionality of Rarlab WinRAR version 7.11. This flaw enables attackers to inject malicious HTML tags into the report generated by the application. When users utilize the 'generate report' command, the tool includes archived file names without adequate validation, which can lead to the exposure of sensitive information such as computer usernames, report directories, and IP addresses if a user opens the compromised report. User interaction is necessary to exploit this vulnerability, making it a significant concern for those utilizing the reporting feature.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52331 : Cross-Site Scripting Vulnerability in Rarlab WinRAR Product