Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xuxueli
Xuxueli xxl-api |
|
| CPEs | cpe:2.3:a:xuxueli:xxl-api:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xuxueli
Xuxueli xxl-api |
Wed, 12 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 12 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-12T21:33:01.596Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60646
Updated: 2025-11-12T21:32:56.114Z
Status : Analyzed
Published: 2025-11-12T19:15:37.013
Modified: 2025-12-03T21:30:51.383
Link: CVE-2025-60646
No data.
OpenCVE Enrichment
No data.