CVE-2025-2616

LOW

yangyouwang crud - XSS

Title source: llm

Description

A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

gitee 656 stars
by yangyouwang · javawriteup
https://gitee.com/yangyouwang/crud/issues/IBSPOX

Scores

CVSS v3 2.4
EPSS 0.0009
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
yangyouwang 杨有旺/crud 简约后台管理系统 1.0.0
Published Mar 22, 2025
Tracked Since Feb 18, 2026