CVE Details
Basic Information
| Title |
CVE-2025-5007 |
| Type |
cve |
| Published |
2025-05-20T23:15:19 |
| Last Seen |
2025-05-21T00:25:10 |
CVSS Information
| Base Score |
3.5 (LOW) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
LOW |
| User Interaction |
REQUIRED |
| Scope |
UNCHANGED |
| Confidentiality Impact |
NONE |
| Integrity Impact |
LOW |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
A cross-site scripting (XSS) vulnerability exists in Part-DB versions up to 1.17.0, specifically in the profile picture feature. The vulnerability allows an attacker to inject malicious scripts via the ‘attachment’ argument in the ‘handleUpload’ function. This can be exploited remotely, potentially compromising user sessions or stealing sensitive information. The issue is addressed in version 1.17.1 with patch 2c4f44e808500db19c391159b30cb6142896d415. |
| AI Severity |
Medium |
| Vendor |
Part-DB |
| Product |
Part-DB |
| Affected Version |
up to 1.17.0 |
Additional Information
| CVE List |
CVE-2025-5007 |
| CWE List |
CWE-94, CWE-79 |
| Bulletin Family |
cve |
Description
A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the file src/Services/Attachments/AttachmentSubmitHandler.php of the component Profile Picture Feature. The manipulation of the argument attachment leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.17.1 is able to address this issue. The identifier of the patch is 2c4f44e808500db19c391159b30cb6142896d415. It is recommended to upgrade the affected component.
CVSS Score Summary
Base Score: %!f(string=#) (LOW)
View Full CVE Details