{"id":"CVE-2025-3965","summary":"itwanger paicoding post cross site scripting","details":"A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.","modified":"2026-05-18T05:59:31.297763277Z","published":"2025-04-27T09:31:04.354Z","database_specific":{"cna_assigner":"VulDB","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3965.json","cwe_ids":["CWE-79","CWE-94"],"unresolved_ranges":[{"extracted_events":[{"last_affected":"1.0.3"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/uglory-gll/javasec/blob/main/paicoding.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3965.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3965"},{"type":"ADVISORY","url":"https://vuldb.com/?id.306301"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.557249"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.306301"},{"type":"EVIDENCE","url":"https://github.com/uglory-gll/javasec/blob/main/paicoding.md#1stored-cross-site-scripting"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/itwanger/paicoding","events":[{"introduced":"0"},{"last_affected":"1fecb6e3135b07e664c3b546ceb74a167c0501f6"}],"database_specific":{"cpe":"cpe:2.3:a:itwanger:paicoding:1.0.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0.3"}],"source":"CPE_FIELD"}}],"versions":["1.0.3-微信支付","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-3965.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}