CVE-2025-65465

MEDIUM

Skrol29 TbsZip <= 2.17 - Reflected Cross-Site Scripting via Filename Parameter

Title source: llm
STIX 2.1

Description

A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earlier allows remote attackers to execute arbitrary web script or HTML via a crafted payload in a filename parameter (e.g., to the FileRead function). This occurs because the error message is not properly sanitized before being output to the user. This vulnerability is fixed in version 2.18.

Scores

CVSS v3 6.1
EPSS 0.0002
EPSS Percentile 7.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Mar 02, 2026
Tracked Since Mar 02, 2026