CVE-2025-2207
CVSS 3.1 Score 2.4 of 10 (low)
Details
Summary
CVE-2025-2207 is a newly disclosed cross-site scripting (XSS) vulnerability affecting the aitangbao springboot-manager version 3.0. The issue lies within the handling of an argument name in the file /sys/dept, which can be exploited remotely. By manipulating this name, an attacker can inject malicious code into a victim's web browser, potentially gaining unauthorized access to sensitive data or performing malicious actions. Although the vendor was notified about the disclosure, they have yet to provide a response or patch for this vulnerability, leaving affected users vulnerable to attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aitangbao Springboot-manager