In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.
CVSS
No CVSS.
References
Configurations
No configuration.
History
22 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-22 15:15
Updated : 2025-10-22 21:12
NVD link : CVE-2025-11966
Mitre link : CVE-2025-11966
CVE.ORG link : CVE-2025-11966
JSON object : View
Products Affected
No product.
