CVE-2025-55288 Information

Description

Genealogy is a family tree PHP application. Prior to 4.4.0 Authenticated Reflected Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another user’s session leading to session hijacking data theft and UI manipulation. This vulnerability is fixed in 4.4.0.

Reference

https://github.com/MGeurts/genealogy/commit/1683b3cbea5e52c99291fa231b7bc8c33f33c33f https://github.com/MGeurts/genealogy/security/advisories/GHSA-3h8x-g9xj-rhwg

CNNVD-202508-2036 (Published: 2025-08-18)

Share on: