CVE-2025-3189 Information
Apr 05, 2025
cve
Description
Stored Cross-Site Scripting (XSS) in DoWISP in versions prior to 1.16.2.50 which consists of an stored XSS through the upload of a profile picture in SVG format with malicious Javascript code in it.
Reference
https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-dowisp
Share on: