Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dbsyncer Project | Dbsyncer | 2.0.6 |
Related Weaknesses (CWE)
References
- http://dbsyncer.comProduct
- https://gist.github.com/chao112122/504e224e63c9a966ba233df1d523ce4fExploitThird Party Advisory
- https://github.com/86dbs/dbsyncerProduct
FAQ
What is CVE-2025-45236?
CVE-2025-45236 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nick...
How severe is CVE-2025-45236?
CVE-2025-45236 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45236?
Check the references section above for vendor advisories and patch information. Affected products include: Dbsyncer Project Dbsyncer.