CVE Details
Basic Information
| Title | atjiu pybbs search cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-08-05T09:32:06.162Z |
| Modified | 2025-08-05T09:32:06.162Z |
Product Information
| Vendor | atjiu |
|---|---|
| Product | pybbs |
| Version | 6.0 |
CVSS Information
| Base Score | 5.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A cross-site scripting (XSS) vulnerability was discovered in the search functionality of atjiu pybbs version 6.0.0. This allows remote attackers to inject malicious scripts via the ‘keyword’ argument. A patch is available to address this issue. |
|---|---|
| AI Severity | Medium |
| AI Vendor | atjiu |
| AI Product | pybbs |
| AI Version | 6.0.0 |
Affected Products
- atjiu pybbs 6.0
Additional Information
| CWE List | CWE-79, CWE-94 |
|---|---|
| Source | VulDB |
Description
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.
References
- https://vuldb.com/?id.318684
- https://vuldb.com/?ctiid.318684
- https://vuldb.com/?submit.622199
- https://github.com/atjiu/pybbs/issues/208
- https://github.com/atjiu/pybbs/issues/208#issuecomment-3134772931
- https://github.com/atjiu/pybbs/issues/208#issue-3256435530
- https://github.com/atjiu/pybbs/commit/2fe4a51afbce0068c291bc1818bbc8f7f3b01a22