PT-2026-22592 · Skrol29 · Tbszip

CVE-2025-65465

·

Published

2026-03-02

·

Updated

2026-03-02

CVSS v3.1

6.1

Medium

VectorAC:L/AV:N/A:N/C:L/I:L/PR:N/S:C/UI:R
Name of the Vulnerable Software and Affected Versions Skrol29 TbsZip versions 2.17 and earlier
Description A reflected Cross-Site Scripting (XSS) issue exists in the RaiseError function of Skrol29 TbsZip. The issue occurs because error messages are not properly sanitized before being displayed to the user. This allows a remote attacker to execute arbitrary web script or HTML by providing a crafted payload within a filename parameter, such as when used with the FileRead function.
Recommendations Update to version 2.18 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65465

Affected Products

Tbszip