Description
A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.
References (3)
Core 3
Core References
Third Party Advisory
https://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2025-45662
Product
https://mp.nnchan.ru/login.php
Scores
CVSS v3
6.1
EPSS
0.0006
EPSS Percentile
18.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Lab Environment
COMMUNITY
Community Lab
Details
CWE
CWE-79
Status
published
Products (1)
nnproject/mpgram_web
2025-04-09
Published
Jul 10, 2025
Tracked Since
Feb 18, 2026