The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21731 The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 18 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Description The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.
Title The Scratch Channel Has Potential Reflected Cross-Site Scripting (XSS) Vulnerability
Weaknesses CWE-692
CWE-79
References
Metrics cvssV4_0

{'score': 1.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-07-18T14:27:37.622Z

Reserved: 2025-07-11T19:05:23.826Z

Link: CVE-2025-53904

cve-icon Vulnrichment

Updated: 2025-07-18T14:27:34.891Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-16T17:15:31.100

Modified: 2025-07-17T21:15:50.197

Link: CVE-2025-53904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.