CVE-2025-5990

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.
References
Link Resource
https://gitlab.com/crafty-controller/crafty-4/-/issues/567 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:craftycontrol:crafty_controller:4.2.0:*:*:*:*:*:*:*

History

11 Aug 2025, 18:46

Type Values Removed Values Added
First Time Craftycontrol crafty Controller
Craftycontrol
References () https://gitlab.com/crafty-controller/crafty-4/-/issues/567 - () https://gitlab.com/crafty-controller/crafty-4/-/issues/567 - Exploit, Issue Tracking
CPE cpe:2.3:a:craftycontrol:crafty_controller:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de neutralización de entrada en los componentes de formulario de nombre de servidor y de formulario de clave API de Crafty Controller permite que un atacante remoto y autenticado realice XSS almacenado a través de una entrada de formulario maliciosa.

15 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-15 18:15

Updated : 2025-08-11 18:46


NVD link : CVE-2025-5990

Mitre link : CVE-2025-5990

CVE.ORG link : CVE-2025-5990


JSON object : View

Products Affected

craftycontrol

  • crafty_controller
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')