CVE-2025-1585
A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5.
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the function OptionsService of the file src/main/resources/templates/themes/default/partial/header.html. The manipulation of the argument logo_url leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- tale project/tale
- Source
- cna@vuldb.com
References
- https://github.com/dragonkeep/cve/blob/main/Tale_Blog_xss.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.296561Permissions Required, VDB Entry
- https://vuldb.com/?id.296561Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.504937Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.