CVE-2025-3393 Details
Description
A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been classified as problematic. This affects an unknown part of the file /ucan-admin/index of the component Personal Settings Interface. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
A cross-site scripting (XSS) vulnerability exists in mrcen springboot-ucan-admin versions up to the commit 5f35162032cbe9288a04e429ef35301545143509. The issue is located in the Personal Settings Interface, specifically within the file '/ucan-admin/index'. This vulnerability can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 8, 2025CISA-ADP
Assessed Apr 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitee.com/mrcen/springboot-ucan-admin/issues/IBT2W5 | CISA-ADP | Issue TrackingTechnical DescriptionVendor |
| https://gitee.com/mrcen/springboot-ucan-admin/issues/IBT2W5 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.303639 | [email protected] | Content Wall |
| https://vuldb.com/?id.303639 | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mrcen springboot-ucan-admin | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2025 | CVE Modified | CISA-ADP |
| Apr 8, 2025 | New CVE Received | [email protected] |
Volerion