CVE-2025-25905 Information

Description

Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the ree\ parameter.

Reference

https://4pace.com/en/products/cadclick https://medium.com/@mdjab3r/cve-2025-25905-ffff82c635f2 https://support.cadclick.com

CNNVD-202506-3171 (Published: 2025-06-25)

Share on: