{"id":63218,"date":"2025-05-18T03:31:56","date_gmt":"2025-05-18T00:01:56","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-4839-itwanger-paicoding-cross-domain-policy-vulnerability\/"},"modified":"2025-05-18T03:31:56","modified_gmt":"2025-05-18T00:01:56","slug":"cve-2025-4839-itwanger-paicoding-cross-domain-policy-vulnerability","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-4839-itwanger-paicoding-cross-domain-policy-vulnerability\/","title":{"rendered":"CVE-2025-4839 &#8211; Itwanger Paicoding Cross-Domain Policy Vulnerability"},"content":{"rendered":"<p><strong>CVE ID : <\/strong>CVE-2025-4839<br \/>\n<br \/>\n<strong>Published : <\/strong> May 17, 2025, 10:15 p.m. | 51\u00a0minutes ago<br \/>\n<br \/>\n<strong>Description : <\/strong>A vulnerability has been found in itwanger paicoding 1.0.0\/1.0.1\/1.0.2\/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file \/paicoding-core\/src\/main\/java\/com\/github\/paicoding\/forum\/core\/util\/CrossUtil.java. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.<br \/>\n<br \/>\n<strong>Severity:<\/strong> 3.1 | LOW<br \/>\n<br \/>\nVisit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-4839 Published : May 17, 2025, 10:15 p.m. | 51\u00a0minutes ago Description : A vulnerability has been found in itwanger paicoding 1.0.0\/1.0.1\/1.0.2\/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file \/paicoding-core\/src\/main\/java\/com\/github\/paicoding\/forum\/core\/util\/CrossUtil.java. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-63218","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/63218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=63218"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/63218\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=63218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=63218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=63218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}