PT-2025-29541 · Unknown · Crosseditor4

CVE-2025-7672

·

Publicado

2025-07-15

·

Atualizado

2025-07-30

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CrossEditor4 versions 4.0.0.01 through 4.6.0.23
Description The improper default setting in the API modules of CrossEditor4 potentially allows Stored Cross-Site Scripting (XSS). Stored XSS is a type of security issue where malicious scripts are persistently stored on the target server and executed in the context of other users' browsers.
Recommendations CrossEditor4 versions prior to 4.6.0.23 should be updated.

Correção

XSS

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-7672

Produtos afetados

Crosseditor4