CVE-2025-13584

Source
https://cve.org/CVERecord?id=CVE-2025-13584
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13584.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13584
Published
2025-11-24T05:16:04.557Z
Modified
2026-03-15T14:52:15.191454Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the component Description Handler. The manipulation of the argument entry.description/time_entry.description leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.4.1 is able to resolve this issue. The identifier of the patch is 7dec94c9d1f3e513e0ee38ba68caaba628e08582. Upgrading the affected component is advised.

References

Affected packages

Git / github.com/eigenfocus/eigenfocus

Affected ranges

Type
GIT
Repo
https://github.com/eigenfocus/eigenfocus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/eigenfocus/eigenfocus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.6.0.rc1
0.9.0.rc3
v0.*
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.0.alpha1
v0.6.0.alpha2
v0.7.0
v0.7.0.alpha1
v0.8.0
v0.8.0.alpha1
v0.8.0.rc1
v0.9.0
v0.9.0.alpha3
v0.9.0.alpha5
v0.9.0.rc1
v0.9.0.rc2
v1.*
v1.0.0-free
v1.0.0.alpha2
v1.0.0.alpha3
v1.0.0.rc1-free
v1.0.0.rc2-free
v1.1.0-free
v1.1.0.rc1-free
v1.2.0-free
v1.2.0.rc1-free
v1.3.0-free
v1.3.0.rc1-free
v1.3.1-free
v1.3.2-free
v1.4.0-free
v1.4.0.rc3-free
v1.4.0.rc4-free
v1.4.0.rc6-free
v1.4.0.rc7-free
v1.4.0.rc8-free
v1.4.0.rc9-free

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13584.json"