CVE-2025-7569 Details
Description
A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerability is the function parse_args of the file /tpl/think_exception.tpl. The manipulation of the argument args leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A reflected cross-site scripting vulnerability has been identified in Bigotry OneBase versions through 1.3.6. The issue arises in the 'parse_args' function within the '/tpl/think_exception.tpl' file, where user-controlled input is not properly sanitized before being outputted. This flaw allows for the injection of arbitrary JavaScript, which can be executed in the context of the admin panel. The vulnerability can be exploited remotely, particularly when an exception is triggered that includes unsanitized input in the call stack trace.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2025CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Hebing123/cve/issues/87 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/?ctiid.316267 | [email protected] | AdvisoryExploit |
| https://vuldb.com/?id.316267 | [email protected] | AdvisoryExploit |
| https://vuldb.com/?submit.607128 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bigotry OneBase | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jul 14, 2025 | New CVE Received | [email protected] |
Volerion