VYPR
Medium severity4.3NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026

CVE-2025-10485

CVE-2025-10485

Description

A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Pojoin/H3bloginferred2 versions
    <=5bf704425ebc11f4c24da51f32f36bb17ae20489+ 1 more
    • (no CPE)range: <=5bf704425ebc11f4c24da51f32f36bb17ae20489
    • (no CPE)range: <=5bf704425ebc11f4c24da51f32f36bb17ae20489

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.