CVE-2025-57205
Last modified
CVE-2025-57205 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is saved and later rendered unsanitized, resulting in JavaScript execution in other users' browsers when they access the affected content. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The application does not enforce a restrictive Content Security Policy (CSP) or adequate filtering to prevent such attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Inilabs | School Express | 6.2 |
References
- https://grumpz.net/cve-2025-57205-stored-xss-in-inilabs-school-express-62-sms-expressExploit, Third Party Advisory
- https://grumpz.net/cve-2025-57205-stored-xss-in-inilabs-school-express-62-sms-expressExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-57205?
How severe is CVE-2025-57205?
How do I fix CVE-2025-57205?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-5720The Customer Reviews for WooCommerce plugin for WordPress is…6.4
- CVE-2025-57200AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1…6.5
- CVE-2025-57201AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1…8.8
- CVE-2025-57202A stored cross-site scripting (XSS) vulnerability in the Pwd…6.1
- CVE-2025-57203MagicProject AI version 9.1 is affected by a Cross-Site Scri…4.8
- CVE-2025-57204Stocky POS with Inventory Management & HRM (ui-lib) version …5.4
- CVE-2025-5721A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-57210Incorrect access control in the component ApiPayController.j…7.5
- CVE-2025-57212Incorrect access control in the component ApiOrderService.ja…7.5
- CVE-2025-57213Incorrect access control in the component orderService.query…7.5
- CVE-2025-57215Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to cont…7.5
- CVE-2025-57217Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discov…5.3
Are you affected by CVE-2025-57205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
