Description

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted by the server and later rendered in another user's Inbox view without appropriate context-aware encoding. As a result, attacker-controlled content executes in the recipient's browser context when the Inbox message is viewed.

INFO

Published Date :

2025-11-12T00:00:00.000Z

Last Modified :

2025-11-13T15:48:25.326Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63645 vulnerability.

Vendors Products
Ph7builder
  • Ph7 Social Dating Builder
Ph7software
  • Ph7-social-dating-cms

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact