CVE-2025-13181

medium

Description

A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/material/add. Executing manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

References

https://vuldb.com/?submit.684887

https://vuldb.com/?id.332471

https://vuldb.com/?ctiid.332471

https://github.com/caigo8/CVE-md/blob/main/h3blog/xss4.md#vulnerability-reproduction

https://github.com/caigo8/CVE-md/blob/main/h3blog/xss4.md

Details

Source: Mitre, NVD

Published: 2025-11-14

Updated: 2025-11-14

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 3.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Severity: Low

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium