Cross-Site Scripting Vulnerability in Rarlab WinRAR Product
CVE-2025-52331
6.1MEDIUM
What is CVE-2025-52331?
A cross-site scripting vulnerability exists in the generate report functionality of Rarlab WinRAR version 7.11. This flaw enables attackers to inject malicious HTML tags into the report generated by the application. When users utilize the 'generate report' command, the tool includes archived file names without adequate validation, which can lead to the exposure of sensitive information such as computer usernames, report directories, and IP addresses if a user opens the compromised report. User interaction is necessary to exploit this vulnerability, making it a significant concern for those utilizing the reporting feature.
