VulnerabilityModified
CVE-2025-13058
The manipulation results in cross site scripting.
MEDIUM 5.1EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The patch is identified as 002def70b985f7012586df2c44368845bf405ab3. Applying a patch is advised to resolve this issue.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- extplorer/extplorer
- Source
- cna@vuldb.com
References
- https://github.com/soerennb/extplorer/
- https://github.com/soerennb/extplorer/commit/002def70b985f7012586df2c44368845bf405ab3Patch
- https://github.com/soerennb/extplorer/issues/33Exploit, Issue Tracking
- https://vuldb.com/?ctiid.332185Permissions Required, VDB Entry
- https://vuldb.com/?id.332185Third Party Advisory, US Government Resource
- https://vuldb.com/?submit.682370Third Party Advisory, US Government Resource
- https://github.com/soerennb/extplorer/issues/33Exploit, Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.