Vulnerability Description
Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function with the xml parameter enabled.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Krpano | Krpano | < 1.23.2 |
Related Weaknesses (CWE)
References
- https://krpano.com/docu/releasenotes/?version=1.23.3Release Notes
- https://krpano.com/forum/wbb/index.php?thread/20554-krpano-1-23-3d-gaussian-splaIssue Tracking
FAQ
What is CVE-2025-65892?
CVE-2025-65892 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQuer...
How severe is CVE-2025-65892?
CVE-2025-65892 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65892?
Check the references section above for vendor advisories and patch information. Affected products include: Krpano Krpano.