CVE Details
Basic Information
| Title | Bigotry OneBase think_exception.tpl parse_args cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-07-14T03:44:04.965Z |
| Modified | 2025-07-14T03:44:04.965Z |
Product Information
| Vendor | Bigotry |
|---|---|
| Product | OneBase |
| Version | 1.3.0 |
CVSS Information
| Base Score | 5.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A cross-site scripting vulnerability exists in Bigotry OneBase up to version 1.3.6. This issue affects the parse_args function in the think_exception.tpl file, allowing remote attackers to execute scripts. The vendor has not responded to the disclosure. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Bigotry |
| AI Product | OneBase |
| AI Version | 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6 |
Affected Products
- Bigotry OneBase 1.3.0
- Bigotry OneBase 1.3.1
- Bigotry OneBase 1.3.2
- Bigotry OneBase 1.3.3
- Bigotry OneBase 1.3.4
- Bigotry OneBase 1.3.5
- Bigotry OneBase 1.3.6
Additional Information
| CWE List | CWE-79, CWE-94 |
|---|---|
| Source | VulDB |
Description
A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerability is the function parse_args of the file /tpl/think_exception.tpl. The manipulation of the argument args leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.