CVE-2025-8506

A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This issue affects some unknown processing of the file /user/editUI. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
Configurations

No configuration.

History

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en 495300897 wx-shop hasta de1b66331368695779cfc6e4d11a64caddf8716e, clasificada como problemática. Este problema afecta a un procesamiento desconocido del archivo /user/editUI. La manipulación provoca Cross-Site Scripting. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. Este producto utiliza el enfoque de lanzamiento continuo para garantizar una distribución continua. Por lo tanto, no se dispone de información sobre las versiones afectadas ni sobre las actualizadas.

03 Aug 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-03 09:15

Updated : 2025-08-04 15:06


NVD link : CVE-2025-8506

Mitre link : CVE-2025-8506

CVE.ORG link : CVE-2025-8506


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')