CVE-2025-5405

A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This issue affects some unknown processing of the file /post.php. The manipulation of the argument comment_author/comment_email/comment_content leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chaitak-gorai:blogbook:*:*:*:*:*:*:*:*

History

10 Nov 2025, 20:04

Type Values Removed Values Added
First Time Chaitak-gorai
Chaitak-gorai blogbook
CPE cpe:2.3:a:chaitak-gorai:blogbook:*:*:*:*:*:*:*:*
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como problemática en chaitak-gorai Blogbook hasta la versión 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Este problema afecta a un procesamiento desconocido del archivo /post.php. La manipulación del argumento comment_author/comment_email/comment_content provoca cross-site-scripting. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. Este producto utiliza el enfoque de versiones continuas para garantizar una entrega continua. Por lo tanto, no se dispone de detalles de las versiones afectadas ni de las actualizadas. Se contactó al proveedor con antelación para informarle sobre esta divulgación, pero no respondió.
References () https://github.com/rllvusgnzm98/Report/blob/main/blogbook/BlogBook%20post.php%20Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Comment%20Functionality%20Leading%20to%20Admin%20and%20User%20Account%20Takeover.md - () https://github.com/rllvusgnzm98/Report/blob/main/blogbook/BlogBook%20post.php%20Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Comment%20Functionality%20Leading%20to%20Admin%20and%20User%20Account%20Takeover.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.310745 - () https://vuldb.com/?ctiid.310745 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.310745 - () https://vuldb.com/?id.310745 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.582925 - () https://vuldb.com/?submit.582925 - Third Party Advisory, VDB Entry

01 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-01 18:15

Updated : 2025-11-10 20:04


NVD link : CVE-2025-5405

Mitre link : CVE-2025-5405

CVE.ORG link : CVE-2025-5405


JSON object : View

Products Affected

chaitak-gorai

  • blogbook
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')