CVE-2025-24885

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo pages causes ability for users to create stored XSS.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) pwn.college es una plataforma educativa para aprender y practicar conceptos básicos de ciberseguridad de manera práctica. La falta de control de acceso al generar páginas de Dojo personalizadas (sin privilegios) hace que los usuarios no puedan crear XSS almacenado.

30 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 23:15

Updated : 2026-06-17 08:59


NVD link : CVE-2025-24885

Mitre link : CVE-2025-24885

CVE.ORG link : CVE-2025-24885


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-284

Improper Access Control