VYPR
Unrated severityNVD Advisory· Published Aug 8, 2025· Updated Aug 8, 2025

CVE-2025-50927

CVE-2025-50927

Description

A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter.

Affected products

2
  • Easy Hosting Control Panel EHCP/EHCPdescription
  • EHCP/EHCPllm-create
    Range: =20.04.1.b

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.