CVE-2025-65754
MEDIUMAlgernon < 1.17.5 - Cross-Site Scripting via Filename Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-65754. PoCs published by Bnyt7.
AI-analyzed exploit summary This PoC demonstrates a stored XSS vulnerability in Algernon 1.17.4, where filenames are not properly sanitized before being rendered in directory listings. The exploit involves creating files with malicious names containing XSS payloads, which execute when accessed via the web interface.
Description
Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.
Exploits (1)
This PoC demonstrates a stored XSS vulnerability in Algernon 1.17.4, where filenames are not properly sanitized before being rendered in directory listings. The exploit involves creating files with malicious names containing XSS payloads, which execute when accessed via the web interface.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N