ZeroHour

CVE-2025-25477

PoC
CVSS 3.1
8.1 high
EPSS
<1%p35
Published
()
Modified
Description

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

Vendors
syspass
Products
syspass
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.