Cross-site Scripting Vulnerability in Web Applications by An Affected Vendor
CVE-2025-55059

4.8MEDIUM

Key Information:

Vendor

Rumpus

Vendor
CVE Published:
17 November 2025

What is CVE-2025-55059?

This vulnerability arises from improper neutralization of user inputs in web applications, enabling attackers to inject malicious scripts. If successfully exploited, this XSS flaw can allow unauthorized access to sensitive information, session hijacking, or manipulation of site content, posing risks to both the application and its users.

Affected Version(s)

FTP Server 9.0.12

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moshe Mizrahi, Almog Cygel, Naor Yaacob
.
CVE-2025-55059 : Cross-site Scripting Vulnerability in Web Applications by An Affected Vendor