CVE-2025-13058 Details
Description
A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The patch is identified as 002def70b985f7012586df2c44368845bf405ab3. Applying a patch is advised to resolve this issue.
A stored cross-site scripting vulnerability has been identified in soerennb eXtplorer versions through 2.1.15. The issue arises in the Filename Handler component, where user-controlled input is not properly sanitized before being outputted, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction. The injected script is executed in the context of the eXtplorer origin, potentially leading to cross-user action hijacking.
Users are advised to update to the patched version of eXtplorer. The patch is available on the eXtplorer GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/soerennb/extplorer/issues/33 | CISA-ADP | ExploitIssue Tracking |
| https://github.com/soerennb/extplorer/ | [email protected] | |
| https://github.com/soerennb/extplorer/commit/002def70b985f7012586df2c44368845bf405ab3 | [email protected] | Patch |
| https://github.com/soerennb/extplorer/issues/33 | [email protected] | ExploitIssue Tracking |
| https://vuldb.com/?ctiid.332185 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.332185 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://vuldb.com/?submit.682370 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| extplorer extplorer | <= 2.1.15 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2026 | CVE Modified | [email protected] |
| Jan 2, 2026 | Initial Analysis | [email protected] |
| Nov 12, 2025 | CVE Modified | CISA-ADP |
| Nov 12, 2025 | New CVE Received | [email protected] |