CVE-2025-3806

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3806 is a newly disclosed vulnerability affecting the dazhouda lecms software up to version 3.0.3. This issue lies within the Edit Profile Handler's /admin file and involves an unknown functionality. Manipulation of this feature can lead to Cross-Site Scripting (XSS), allowing attackers to inject malicious code into a user's browser. The exploit can be executed remotely, posing a significant threat to system security. Public disclosure of the exploit increases the risk of successful attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share