Stored Cross-Site Scripting Vulnerability in pH7Software's Social Dating CMS
CVE-2025-63645

5.4MEDIUM

Key Information:

Vendor
CVE Published:
12 November 2025

What is CVE-2025-63645?

A stored cross-site scripting vulnerability exists within the messaging system of pH7Software's pH7-Social-Dating-CMS version 17.9.1. The flaw arises when unsanitized message content submitted by a user is stored on the server and later displayed in another user's Inbox view without proper context-aware encoding. This oversight allows an attacker to inject malicious scripts that execute whenever the recipient views the affected message, potentially leading to unauthorized actions or data exposure in the user's browser.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.