CNNVD-202506-3030 Information

CNNVD ID

CNNVD-202506-3030

CVE-2025-6551

  • CNNVD Published: 2025-06-24

Description (Chinese)

Hope-Boot是java-aodeng个人开发者的一款现代化的脚手架项目。 Hope-Boot 1.0.0版本存在安全漏洞,该漏洞源于WebController.java中Login函数对参数errorMsg处理不当,可能导致跨站脚本攻击。

Description (English)

Hope-Boot is a modern scaffolding project for Java-aodeng personal developers. There is a security loophole in Hope-Boot 1.00, which stems from the inappropriate handling of the argumenterMsg by the Login function in WebController.java, which may result in a cross-site script attack.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

Live Support

Published

2025-06-24

Last Modified

2026-02-24

References

https://vuldb.com/?id.313691 https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250613-01/report.md https://vuldb.com/?ctiid.313691 https://vuldb.com/?submit.596615 https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250613-01/report.md#steps-to-reproduce https://access.redhat.com/security/cve/cve-2025-6551

Share on: