PT-2025-46688 · Xxl-Api · Xxl-Api

CVE-2025-60646

·

Published

2025-11-12

·

Updated

2025-12-04

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Xxl-api version 1.3.0
Description A stored cross-site scripting (XSS) issue exists in the Business Line Management module. This allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Name parameter.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider sanitizing the Name parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60646

Affected Products

Xxl-Api