CVE-2025-5990

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.
Configurations

No configuration.

History

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de neutralización de entrada en los componentes de formulario de nombre de servidor y de formulario de clave API de Crafty Controller permite que un atacante remoto y autenticado realice XSS almacenado a través de una entrada de formulario maliciosa.

15 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-15 18:15

Updated : 2025-06-16 12:32


NVD link : CVE-2025-5990

Mitre link : CVE-2025-5990

CVE.ORG link : CVE-2025-5990


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')