CVE-2025-2617

LOW

yangyouwang crud - XSS

Title source: llm

Description

A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

gitee 656 stars
by yangyouwang · javawriteup
https://gitee.com/yangyouwang/crud/issues/IBSPOX

Scores

CVSS v3 2.4
EPSS 0.0007
EPSS Percentile 21.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
yangyouwang 杨有旺/crud 简约后台管理系统 1.0.0
Published Mar 22, 2025
Tracked Since Feb 18, 2026