CVE 5.1 MEDIUM

Reflected XSS in Lepszy BIP_CVE-2025-7761

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of the parameters allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened.

The vendor was contacted early about this disclosure but did not respond in any way. Potentially all versions are vulnerable.

Basic Information

ID CVE-2025-7761
Source CERT-PL
Published Aug 14, 2025 at 10:01

Affected Product

Vendor Akcess-Net
Product Lepszy BIP
Affected Versions Akcess-Net Lepszy BIP 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.