5.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Description
Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another userβs session, leading to session hijacking, data theft, and UI manipulation. This vulnerability is fixed in 4.4.0.
Basic Information
ID
CVE-2025-55288
Source
GitHub_M
Published
Aug 18, 2025 at 16:57
Affected Product
Vendor
MGeurts
Product
genealogy
Version
< 4.4.0
Affected Versions
MGeurts genealogy < 4.4.0