CVE-2025-25477

Source
https://cve.org/CVERecord?id=CVE-2025-25477
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25477.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-25477
Published
2025-02-28T00:15:36.380Z
Modified
2026-04-10T05:23:17.465650Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

References

Affected packages

Git / github.com/nuxsmin/syspass

Affected ranges

Type
GIT
Repo
https://github.com/nuxsmin/syspass
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.2.0"
        },
        {
            "last_affected": "3.2.11"
        }
    ]
}

Affected versions

3.*
3.2.0
3.2.1
3.2.10
3.2.11
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25477.json"