CVE-2025-2352
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-2352 is a recently disclosed vulnerability affecting StarSea99's starsea-mall 1.0. The issue lies in the Backend component's processing of the /admin/indexConfigs/save file, where the argument categoryName is manipulable. This results in cross-site scripting (XSS) vulnerabilities, which can be exploited remotely. Although the vendor was notified, no response was received, and the public now has access to the exploit. Unfortunately, due to the product's lack of versioning, it is unclear which releases are affected or unaffected. Other parameters might also be susceptible to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.