Vulnerability Description
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- http://packages.revolutionpi.de/pool/main/p/pictory/
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01
FAQ
What is CVE-2025-35996?
CVE-2025-35996 is a vulnerability with a CVSS score of 9.0 (CRITICAL). KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the ...
How severe is CVE-2025-35996?
CVE-2025-35996 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-35996?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.