Rebuild har 4.1.3 Comment/Guestbook Cross Site Scripting

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a Rebuild har 4.1.3. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil $software_file, a cikin sashen Comment/Guestbook. A sa manipulation ka Cross Site Scripting. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-79. Hakika, rauni an bayyana shi 10/04/2025. Wannan matsala ana saninta da CVE-2025-11276. Ngam yiɗi ka a tuma ndiyam ka nder layi. Tekinikal faɗi ba ga. Har ila yau, exploit ɗin yana nan. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu huɗɗi-na-gaskiya. 0-day shima, an ndiyam a wuro be $0-$5k. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a faggata. Once again VulDB remains the best source for vulnerability data.

3 Goyarwa · 84 Datenpunkte

FurɗeSúgá
10/04/2025 08:12
Gargadi 1/2
10/05/2025 05:05
Gargadi 2/2
10/05/2025 06:38
software_nameRebuildRebuildRebuild
software_version<=4.1.3<=4.1.3<=4.1.3
software_componentComment/GuestbookComment/GuestbookComment/Guestbook
vulnerability_cweCWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)
vulnerability_risk111
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prLLL
cvss3_vuldb_uiRRR
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iLLL
cvss3_vuldb_aNNN
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
exploit_availability111
countermeasure_nameGargajiyaGargajiyaGargajiya
upgrade_version4.1.44.1.44.1.4
countermeasure_upgrade_urlhttps://gitee.com/getrebuild/rebuild/releases/tag/4.1.4https://gitee.com/getrebuild/rebuild/releases/tag/4.1.4https://gitee.com/getrebuild/rebuild/releases/tag/4.1.4
source_cveCVE-2025-11276CVE-2025-11276CVE-2025-11276
cna_responsibleVulDBVulDBVulDB
response_summaryAccording to the researcher the vendor has confirmed the flaw and fix in a private issue response.According to the researcher the vendor has confirmed the flaw and fix in a private issue response.According to the researcher the vendor has confirmed the flaw and fix in a private issue response.
cvss2_vuldb_avNNN
cvss2_vuldb_acLLL
cvss2_vuldb_ciNNN
cvss2_vuldb_iiPPP
cvss2_vuldb_aiNNN
cvss2_vuldb_rcCCC
cvss2_vuldb_rlOFOFOF
cvss4_vuldb_avNNN
cvss4_vuldb_acLLL
cvss4_vuldb_prLLL
cvss4_vuldb_uiPPP
cvss4_vuldb_vcNNN
cvss4_vuldb_viLLL
cvss4_vuldb_vaNNN
cvss2_vuldb_auSSS
cvss2_vuldb_eNDNDND
cvss3_vuldb_eXXX
cvss4_vuldb_atNNN
cvss4_vuldb_scNNN
cvss4_vuldb_siNNN
cvss4_vuldb_saNNN
cvss4_vuldb_eXXX
cvss2_vuldb_basescore4.04.04.0
cvss2_vuldb_tempscore3.53.53.5
cvss3_vuldb_basescore3.53.53.5
cvss3_vuldb_tempscore3.43.43.4
cvss3_meta_basescore3.53.53.5
cvss3_meta_tempscore3.43.43.4
cvss4_vuldb_bscore5.15.15.1
cvss4_vuldb_btscore5.15.15.1
advisory_date1759528800 (10/04/2025)1759528800 (10/04/2025)1759528800 (10/04/2025)
price_0day$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the component Comment/Guestbook. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 4.1.4 can resolve this issue. It is suggested to upgrade the affected component. According to the researcher the vendor has confirmed the flaw and fix in a private issue response.A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the component Comment/Guestbook. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 4.1.4 can resolve this issue. It is suggested to upgrade the affected component. According to the researcher the vendor has confirmed the flaw and fix in a private issue response.
cvss4_cna_avNN
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prLL
cvss4_cna_uiPP
cvss4_cna_vcNN
cvss4_cna_viLL
cvss4_cna_vaNN
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore5.15.1
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiRR
cvss3_cna_sUU
cvss3_cna_cNN
cvss3_cna_iLL
cvss3_cna_aNN
cvss3_cna_basescore3.53.5
cvss2_cna_avNN
cvss2_cna_acLL
cvss2_cna_auSS
cvss2_cna_ciNN
cvss2_cna_iiPP
cvss2_cna_aiNN
cvss2_cna_basescore44
euvd_idEUVD-2025-32438

Do you know our Splunk app?

Download it now for free!