CVE-2025-25477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
28/02/2025
Last modified:
09/07/2025

Description

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:syspass:syspass:*:*:*:*:*:*:*:* 3.2.0 (including) 3.2.11 (including)


References to Advisories, Solutions, and Tools