Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 25 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 25 Sep 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects the function ip of the file ip.php. This manipulation of the argument callback causes cross site scripting. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | yi-ge get-header-ip ip.php cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-25T13:07:01.730Z
Reserved: 2025-09-25T05:54:41.484Z
Link: CVE-2025-10944

Updated: 2025-09-25T13:06:59.192Z

Status : Received
Published: 2025-09-25T13:15:30.800
Modified: 2025-09-25T13:15:30.800
Link: CVE-2025-10944

No data.

No data.