Cross-Site Scripting Vulnerability in jsnjfz WebStack-Guns File Upload Component
CVE-2025-5887
Key Information:
- Vendor
Jsnjfz
- Status
- Vendor
- CVE Published:
- 9 June 2025
Badges
What is CVE-2025-5887?
A flaw has been identified in the jsnjfz WebStack-Guns 1.0 application related to its file upload functionality. Specifically, a vulnerability exists in the UserMgrController.java file which allows the manipulation of the File upload argument. This can lead to cross-site scripting (XSS) attacks, potentially enabling an attacker to execute malicious scripts in a user's browser. This vulnerability can be exploited remotely, posing significant security risks for users. Despite the vulnerability being disclosed publicly, there has been no response from the vendor regarding the issue, leaving users without guidance or remedies.
Affected Version(s)
WebStack-Guns 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved