CVE-2025-7380 Details
Description
A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to inject malicious scripts into the folder name field while creating a new shared folder. These scripts are not properly sanitized and will be executed when the folder name is subsequently displayed in the user interface. This allows attackers to execute arbitrary JavaScript in the context of another user's session, potentially accessing session cookies or other sensitive data. Affected products and versions include: from ADM 4.1.0 to ADM 4.3.3.RH61 as well as ADM 5.0.0.RIN1 and earlier.
A stored Cross-Site Scripting vulnerability has been identified in the Access Control of ASUSTOR's ADM. This vulnerability allows attackers to inject malicious scripts into the folder name field when creating a new shared folder. The injected scripts are not properly sanitized and are executed when the folder name is displayed in the user interface. This could enable attackers to execute arbitrary JavaScript in the context of another user's session, potentially accessing session cookies or other sensitive information. The vulnerability affects ASUSTOR ADM versions 4.1.0 through 4.3.3.RH61, as well as ADM 5.0.0.RIN1 and earlier.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2025CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asustor.com/security/security_advisory_detail?id=44 | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ASUSTOR ADM | >= 4.1.0, <= 4.3.3.RH61 <= 5.0.0.RIN1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | New CVE Received | [email protected] |
Volerion