216.73.216.197

CVE-2025-63693

· Published 18/11/2025 19:15 · Modified 20/11/2025 20:07

Labels: CVE-2025-63693 2025-11-18CVE-2025-63693CWE-94[email protected]

Essential information

Published
18/11/2025 19:15
Modified
20/11/2025 20:07
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attackers to construct comment content or request parameters and execute arbitrary JavaScript code when the victim opens the editing pop-up.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dzzoffice / dzzoffice cpe:2.3:a:dzzoffice:dzzoffice:*:*:*:*:*:*:*:*

References