Cross Site Scripting Vulnerability in Schlix CMS Login Form
CVE-2025-67443

6.1MEDIUM

Key Information:

Vendor

Schlix

Vendor
CVE Published:
22 December 2025

What is CVE-2025-67443?

Schlix CMS versions before 2.2.9-5 are exposed to a Cross Site Scripting (XSS) vulnerability within the login form. This flaw arises from inadequate sanitization of JavaScript in the login interface, leading to the potential execution of malicious scripts when incorrect login attempts are logged. Administrators may encounter XSS during routine operations within the admin panel, creating risk for data exposure and administrative functions. It is crucial for users to update their installations to mitigate this security risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.