Home

Description

EN DE

A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The patch is identified as 002def70b985f7012586df2c44368845bf405ab3. Applying a patch is advised to resolve this issue.

Es wurde eine Schwachstelle in soerennb eXtplorer up to 2.1.15 entdeckt. Dabei geht es um eine nicht genauer bekannte Funktion der Komponente Filename Handler. Durch das Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff lässt sich über das Netzwerk starten. Der Name des Patches ist 002def70b985f7012586df2c44368845bf405ab3. Als bestmögliche Massnahme wird Patching empfohlen.

PUBLISHED Reserved 2025-11-12 | Published 2025-11-12 | Updated 2025-11-12 | Assigner VulDB




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
LOW: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C
LOW: 3.5CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C
4.0AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:OF/RC:C

Problem types

Cross Site Scripting

Code Injection

Product status

2.1.0
affected

2.1.1
affected

2.1.2
affected

2.1.3
affected

2.1.4
affected

2.1.5
affected

2.1.6
affected

2.1.7
affected

2.1.8
affected

2.1.9
affected

2.1.10
affected

2.1.11
affected

2.1.12
affected

2.1.13
affected

2.1.14
affected

2.1.15
affected

Timeline

2025-11-12:Advisory disclosed
2025-11-12:VulDB entry created
2025-11-12:VulDB entry last update

Credits

NomanProdhan (VulDB User) reporter

References

github.com/soerennb/extplorer/issues/33 exploit

vuldb.com/?id.332185 (VDB-332185 | soerennb eXtplorer Filename cross site scripting) vdb-entry

vuldb.com/?ctiid.332185 (VDB-332185 | CTI Indicators (IOB, IOC, TTP)) signature permissions-required

vuldb.com/?submit.682370 (Submit #682370 | eXtplorer eXtplorer (PHP file manager) 2.1.15 Cross-Site Scripting (Stored)) third-party-advisory

github.com/soerennb/extplorer/issues/33 issue-tracking

github.com/...ommit/002def70b985f7012586df2c44368845bf405ab3 patch

cve.org (CVE-2025-13058)

nvd.nist.gov (CVE-2025-13058)

Download JSON