Description
Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
Published: 2025-03-24
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7916 Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
History

Tue, 29 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Uguu
Uguu uguu
CPEs cpe:2.3:a:uguu:uguu:*:*:*:*:*:*:*:*
Vendors & Products Uguu
Uguu uguu

Tue, 01 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-01T18:06:38.362Z

Reserved: 2024-12-06T00:00:00.000Z

Link: CVE-2024-55279

cve-icon Vulnrichment

Updated: 2025-04-01T18:05:58.504Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-24T15:15:15.913

Modified: 2025-04-29T18:12:55.493

Link: CVE-2024-55279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses