CVE-2025-2208

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Mar 11, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-2208 is a newly disclosed vulnerability affecting the Filename Handler component in aitangbao springboot-manager version 3.0. This issue is classified as problematic due to the potential for cross-site scripting (XSS) attacks. Manipulation of the argument name in the /sysFiles/upload file can lead to XSS, allowing remote attackers to inject malicious scripts into unsuspecting users' browsers. The vulnerability has been made public, and the exploit is currently in circulation, despite the vendor's lack of response to early disclosures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share