CVE 2.3 LOW

CVE-2025-11966_CVE-2025-11966

2.3 / 10
LOW
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Description

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.

Basic Information

ID CVE-2025-11966
Source eclipse
Published Oct 22, 2025 at 14:44
Modified Oct 22, 2025 at 15:26

Affected Product

Vendor Eclipse Foundation
Product Vert.x
Version 4.0.0
Affected Versions Eclipse Foundation Vert.x 4.0.0
Eclipse Foundation Vert.x 5.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.