A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Tue, 17 Jun 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Hkcms
Hkcms hkcms
CPEs cpe:2.3:a:hkcms:hkcms:2.3.2.240702:*:*:*:*:*:*:*
Vendors & Products Hkcms
Hkcms hkcms

Wed, 21 May 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 May 2025 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title HkCms Search index.html cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-21T00:31:23.395Z

Updated: 2025-05-21T22:13:41.928Z

Reserved: 2025-05-20T16:02:33.101Z

Link: CVE-2025-5013

cve-icon Vulnrichment

Updated: 2025-05-21T22:13:34.302Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-21T06:16:29.103

Modified: 2025-06-17T14:10:53.597

Link: CVE-2025-5013

cve-icon Redhat

No data.