Vulnerability Description
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML response, allowing attackers to inject and execute arbitrary JavaScript when a victim visits a maliciously crafted URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Diskoverdata | Diskover | 2.3.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-50985?
CVE-2025-50985 is a vulnerability with a CVSS score of 5.6 (MEDIUM). diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (...
How severe is CVE-2025-50985?
CVE-2025-50985 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50985?
Check the references section above for vendor advisories and patch information. Affected products include: Diskoverdata Diskover.