Home

Description

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-17 | Updated 2025-12-17 | Assigner mitre

References

github.com/slims/slims9_bulian/issues/185

github.com/...ulnerability-research/tree/main/CVE-2025-65233

cve.org (CVE-2025-65233)

nvd.nist.gov (CVE-2025-65233)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.