CVE Details
Basic Information
| Title |
CVE-2025-5013 HkCms Search index.html cross site scripting |
| Type |
cve |
| Published |
2025-05-21T00:31:23 |
| Last Seen |
2025-05-21T01:03:38 |
CVSS Information
| Base Score |
0.0 () |
| Attack Vector |
|
| Attack Complexity |
|
| Privileges Required |
|
| User Interaction |
|
| Scope |
|
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
A cross-site scripting (XSS) vulnerability was found in the search functionality of HkCms up to version 2.3.2.240702. The issue allows attackers to inject arbitrary web scripts or HTML via the search argument, potentially compromising user interactions with the website. |
| AI Severity |
Medium |
| Vendor |
HkCms |
| Product |
HkCms |
| Affected Version |
up to 2.3.2.240702 |
Additional Information
| CVE List |
CVE-2025-5013 |
| CWE List |
CWE-94, CWE-79 |
| Bulletin Family |
cve |
Description
A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument…
CVSS Score Summary
Base Score: %!f(string=#) ()
View Full CVE Details