CVE-2025-6551
Last modified
CVE-2025-6551 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Java-Aodeng | Hope-Boot | 1.0.0 |
References
- https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250613-01/report.mdExploit, Third Party Advisory
- https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250613-01/report.md#steps-to-reproduceExploit, Third Party Advisory
- https://vuldb.com/?ctiid.313691Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.313691Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.596615Third Party Advisory, VDB Entry
- https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250613-01/report.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6551?
How severe is CVE-2025-6551?
How do I fix CVE-2025-6551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-65499Array index error in tls_verify_call_back() in src/coap_open…4.3
- CVE-2025-6550The The Pack Elementor addon plugin for WordPress is vulnera…5.4
- CVE-2025-65500NULL pointer dereference in coap_dtls_generate_cookie() in s…4.3
- CVE-2025-65501Null pointer dereference in coap_dtls_info_callback() in OIS…4.3
- CVE-2025-65502Null pointer dereference in add_ca_certs() in Cesanta Mongoo…4.3
- CVE-2025-65503Use after free in endpoint destructors in Redboltz async_mqt…5.5
- CVE-2025-65512A Server-Side Request Forgery (SSRF) vulnerability was disco…7.5
- CVE-2025-65513fetch-mcp v1.0.2 and before is vulnerable to Server-Side Req…7.5
- CVE-2025-65516A stored cross-site scripting (XSS) vulnerability was discov…6.1
- CVE-2025-65518Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable…7.5
- CVE-2025-65519mayswind ezbookkeeping versions 1.2.0 and earlier contain a …6.5
- CVE-2025-6552A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It…4.3
Are you affected by CVE-2025-6551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
