CVE-2025-2207

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Mar 11, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-2207 is a newly disclosed cross-site scripting (XSS) vulnerability affecting the aitangbao springboot-manager version 3.0. The issue lies within the handling of an argument name in the file /sys/dept, which can be exploited remotely. By manipulating this name, an attacker can inject malicious code into a victim's web browser, potentially gaining unauthorized access to sensitive data or performing malicious actions. Although the vendor was notified about the disclosure, they have yet to provide a response or patch for this vulnerability, leaving affected users vulnerable to attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share