Vulnerability Details
Basic Information
| Title | CVE-2025-29512 |
|---|---|
| Type | nvd |
| Published | 2025-04-18T18:15:48 |
| Last Seen | 2025-04-18T19:19:51 |
| CVSS Score | 6.1 (MEDIUM) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | CHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2025-29512 |
|---|---|
| CWE | CWE-79 |
| Bulletin Family | cve |
Description
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.
Impact Assessment
| Base Score | 6.1 |
|---|---|
| Severity | MEDIUM |