CVE-2025-65892 – Krpano Reflected Cross-Site Scripting (rXSS)

CVE ID : CVE-2025-65892

Published : Nov. 29, 2025, 4:15 a.m. | 2 hours, 8 minutes ago

Description : Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim’s browser via a crafted URL to the passQueryParameters function with the xml parameter enabled.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه