PoC Index

CVE-2025-25477

HIGH 8.1EPSS 0.4%

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS
0.41% chance of exploitation in the next 30 days, 34th percentile
Published
2025-02-27
Updated
2025-02-28

Proof-of-concept exploits (1)

References

Related