Metrics
Affected Vendors & Products
Thu, 25 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Sep 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects the function ip of the file ip.php. This manipulation of the argument callback causes cross site scripting. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | yi-ge get-header-ip ip.php cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-25T12:32:06.378Z
Updated: 2025-09-25T13:07:01.730Z
Reserved: 2025-09-25T05:54:41.484Z
Link: CVE-2025-10944
Updated: 2025-09-25T13:06:59.192Z
Status : Awaiting Analysis
Published: 2025-09-25T13:15:30.800
Modified: 2025-09-26T14:32:53.583
Link: CVE-2025-10944
No data.