PT-2026-48266 · Evoluted · Directory Listing Script

·

CVE-2026-25557

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Evoluted PHP Directory Listing Script versions prior to 4.0.6
Description A reflected cross-site scripting issue exists in the 'index.php' endpoint. The dir parameter is reflected without HTML encoding within the HTML title element and the anchor href attributes of the breadcrumb navigation. This allows attackers to execute arbitrary JavaScript in a victim's browser by breaking out of the title context or injecting event handlers into the breadcrumb anchor attributes.
Recommendations Update to a version newer than 4.0.5. As a temporary mitigation, avoid using the dir parameter in the 'index.php' endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25557

Affected Products

Directory Listing Script