CVE-2025-8211 MEDIUM

CVE-2025-8211: Roothub SystemConfigAdminController.java edit cross site scripting

Vendor N/A
Product Roothub
Weakness CWE-79 · XSS
Published July 26, 2025
Last update July 28, 2025

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Key dates

Disclosure timeline

July 26, 2025 CVE published
July 28, 2025 Record updated