CVE-2025-5007

CVE Details

Basic Information

Title CVE-2025-5007
Type cve
Published 2025-05-20T23:15:19
Last Seen 2025-05-21T00:25:10

CVSS Information

Base Score 3.5 (LOW)
Attack Vector NETWORK
Attack Complexity LOW
Privileges Required LOW
User Interaction REQUIRED
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact LOW
Availability Impact NONE

AI Analysis

AI Description A cross-site scripting (XSS) vulnerability exists in Part-DB versions up to 1.17.0, specifically in the profile picture feature. The vulnerability allows an attacker to inject malicious scripts via the ‘attachment’ argument in the ‘handleUpload’ function. This can be exploited remotely, potentially compromising user sessions or stealing sensitive information. The issue is addressed in version 1.17.1 with patch 2c4f44e808500db19c391159b30cb6142896d415.
AI Severity Medium
Vendor Part-DB
Product Part-DB
Affected Version up to 1.17.0

Additional Information

CVE List CVE-2025-5007
CWE List CWE-94, CWE-79
Bulletin Family cve

Description

A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the file src/Services/Attachments/AttachmentSubmitHandler.php of the component Profile Picture Feature. The manipulation of the argument attachment leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.17.1 is able to address this issue. The identifier of the patch is 2c4f44e808500db19c391159b30cb6142896d415. It is recommended to upgrade the affected component.

CVSS Score Summary

Base Score: %!f(string=#) (LOW)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.