CVE-2025-55473
Last modified
CVE-2025-55473 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows an attacker to inject malicious JavaScript code that will execute in visitor browsers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-55473?
How severe is CVE-2025-55473?
How do I fix CVE-2025-55473?
Are you affected by CVE-2025-55473?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
