Vulnerability Description
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ehcp | Easy Hosting Control Panel | 20.04.1.b |
Related Weaknesses (CWE)
References
- https://packetstorm.news/files/id/207908Broken Link
- https://www.ehcp.net/?p=402Product
FAQ
What is CVE-2025-50927?
CVE-2025-50927 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload...
How severe is CVE-2025-50927?
CVE-2025-50927 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50927?
Check the references section above for vendor advisories and patch information. Affected products include: Ehcp Easy Hosting Control Panel.