A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try to access the infected codebox by clicking link or entering share code.
References
| Link | Resource |
|---|---|
| https://github.com/vastsa/FileCodeBox | Product |
| https://github.com/vastsa/FileCodeBox/issues/351 | Exploit Issue Tracking |
| https://github.com/vastsa/FileCodeBox/issues/351 | Exploit Issue Tracking |
Configurations
History
24 Nov 2025, 19:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/vastsa/FileCodeBox - Product | |
| References | () https://github.com/vastsa/FileCodeBox/issues/351 - Exploit, Issue Tracking | |
| CPE | cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:* | |
| First Time |
Lanol filecodebox
Lanol |
20 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/vastsa/FileCodeBox/issues/351 - | |
| CWE | CWE-79 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
19 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 20:15
Updated : 2025-11-24 19:40
NVD link : CVE-2025-51662
Mitre link : CVE-2025-51662
CVE.ORG link : CVE-2025-51662
JSON object : View
Products Affected
lanol
- filecodebox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
