PT-2025-40975 · Jakowenko · Jakowenko Double-Take

·

CVE-2025-11360

·

Published

2025-10-07

·

Updated

2025-10-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions jakowenko double-take versions up to 1.13.1
Description A flaw exists in the API component of jakowenko double-take. The issue is related to the app.use function within the api/src/app.js file. Manipulation of the X-Ingress-Path argument can lead to cross-site scripting. This attack can be carried out remotely.
Recommendations Upgrade to version 1.13.2 or later to resolve this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11360

Affected Products

Jakowenko Double-Take