Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19761 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on Linux, MacOS allows Account Takeover. This issue affects Laundry: 2.3.0. |
Tue, 23 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Laundry Project Laundry Project laundry Linux Linux linux Kernel |
|
| CPEs | cpe:2.3:a:laundry_project:laundry:2.3.0:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple macos Laundry Project Laundry Project laundry Linux Linux linux Kernel |
|
| Metrics |
cvssV3_1
|
Wed, 02 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on Linux, MacOS allows Account Takeover. This issue affects Laundry: 2.3.0. | |
| Title | Laundry 2.3.0 - Account Takeover via Reflected XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-07-02T20:10:11.456Z
Reserved: 2025-06-19T23:44:06.220Z
Link: CVE-2025-52842
Updated: 2025-07-02T20:09:00.227Z
Status : Analyzed
Published: 2025-07-02T20:15:31.727
Modified: 2025-12-23T20:45:48.510
Link: CVE-2025-52842
No data.
OpenCVE Enrichment
No data.
EUVD