Reflected Cross-Site Scripting in PRIMER by chloƩdigital
CVE-2025-68873
7.1HIGH
What is CVE-2025-68873?
The improper neutralization of input during web page generation in PRIMER by chloƩdigital makes it susceptible to reflected cross-site scripting (XSS) attacks. Attackers can exploit this flaw to inject malicious scripts through user input fields, leading to unauthorized actions on behalf of users and potential data theft. This vulnerability affects versions of the software up to and including 1.0.25, necessitating immediate attention and remediation to protect user data and maintain site integrity.
Affected Version(s)
PRIMER by chloƩdigital <= n/a
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien | Patchstack Bug Bounty Program