CVE-2025-25203

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 11, 2025
CWE ID 79

Summary

CVE-2025-25203 is a Cross-Site Scripting (XSS) vulnerability affecting the open-source billing software CtrlPanel before version 1.0. The issue lies in the insufficient input validation on the 'priority' field during ticket creation, which can lead to the injection of malicious scripts. These scripts can be executed when a moderator views the affected ticket in their panel, posing a significant security risk. Version 1.0 of CtrlPanel includes a patch to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share