CVE-2025-35996
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.
Scoring
- Severity
- HIGH
- CVSS base score
- 9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 17.34%
- CWE
- CWE-97
- Published
- 2025-05-01
- Last modified
- 2026-03-12
Affected products
- KUNBUS GmbH Revolution Pi PiCtory
Weakness type
Related vulnerabilities
- CVE-2023-53934 — Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service
- CVE-2025-36558 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-21103 — Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7...
- CVE-2024-56363 — APTRS has SSTI vulnerability