CVE-2025-1553

A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project. The manipulation of the argument goal leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Configurations

No configuration.

History

24 Feb 2025, 17:15

Type Values Removed Values Added
References
  • () https://docs.google.com/document/d/1r8Ad7Kaw0bwKZMVFDlhzhpjdque7vRGTDKDeP7yiUEc/edit?tab=t.0#heading=h.ukpd7mmeqiqp -
Summary
  • (es) Se encontró una vulnerabilidad en pankajindevops escalable hasta 3633544a00245d3df88b6d13d9b3dd0f411be7f6. Se ha clasificado como problemática. Se ve afectada una función desconocida del archivo /scale/project. La manipulación del argumento goal provoca cross site scripting. Es posible lanzar el ataque de forma remota. El exploit se ha divulgado al público y puede utilizarse. Este producto utiliza la entrega continua con versiones sucesivas. Por lo tanto, no hay disponibles detalles de las versiones afectadas ni de las versiones actualizadas.

22 Feb 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-22 10:15

Updated : 2025-02-24 17:15


NVD link : CVE-2025-1553

Mitre link : CVE-2025-1553

CVE.ORG link : CVE-2025-1553


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')