PT-2025-15324 · Unknown · Vulnerability-Lookup

CVE-2025-32413

·

Published

2025-04-08

·

Updated

2025-04-08

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Vulnerability-Lookup versions prior to 2.7.1
Description: The issue allows stored XSS via a user bio in the website/web/views/user.py file. This can potentially lead to malicious script execution when a user views the affected bio.
Recommendations: For versions prior to 2.7.1, consider disabling the user bio feature in website/web/views/user.py until a patch is available. Restrict access to the user bio section to minimize the risk of exploitation. Avoid displaying user bios from untrusted sources in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32413

Affected Products

Vulnerability-Lookup