Cross-Site Scripting Vulnerability in jsnjfz WebStack-Guns File Upload Component
CVE-2025-5887

5.1MEDIUM

Key Information:

Vendor

Jsnjfz

Vendor
CVE Published:
9 June 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-5887?

A flaw has been identified in the jsnjfz WebStack-Guns 1.0 application related to its file upload functionality. Specifically, a vulnerability exists in the UserMgrController.java file which allows the manipulation of the File upload argument. This can lead to cross-site scripting (XSS) attacks, potentially enabling an attacker to execute malicious scripts in a user's browser. This vulnerability can be exploited remotely, posing significant security risks for users. Despite the vulnerability being disclosed publicly, there has been no response from the vendor regarding the issue, leaving users without guidance or remedies.

Affected Version(s)

WebStack-Guns 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

aiyakami (VulDB User)
.
CVE-2025-5887 : Cross-Site Scripting Vulnerability in jsnjfz WebStack-Guns File Upload Component