A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
References
Configurations
No configuration.
History
16 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/hhhh333/CVE/blob/main/xss.md - |
15 Sep 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 23:15
Updated : 2025-09-16 14:15
NVD link : CVE-2025-10485
Mitre link : CVE-2025-10485
CVE.ORG link : CVE-2025-10485
JSON object : View
Products Affected
No product.