Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of the parameters allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened. The vendor was contacted early about this disclosure but did not respond in any way. Potentially all versions are vulnerable.
History

Thu, 14 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 10:15:00 +0000

Type Values Removed Values Added
Description Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of the parameters allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened. The vendor was contacted early about this disclosure but did not respond in any way. Potentially all versions are vulnerable.
Title Reflected XSS in Lepszy BIP
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-08-14T10:01:38.710Z

Updated: 2025-08-14T14:49:01.373Z

Reserved: 2025-07-17T14:06:46.777Z

Link: CVE-2025-7761

cve-icon Vulnrichment

Updated: 2025-08-14T13:36:08.673Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-14T10:15:29.300

Modified: 2025-08-14T15:15:42.117

Link: CVE-2025-7761

cve-icon Redhat

No data.