Vulnerability advisory

CVE-2025-13058

Research by Md. Moniruzzaman Prodhan November 12, 2025
Overview

Summary

A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The patch is identified as 002def70b985f7012586df2c44368845bf405ab3. Applying a patch is advised to resolve this issue.

Risk profile

CVSS assessment

5.1 · M E D I U M
Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack vector
N E T W O R K
Complexity
L O W
Privileges
L O W
User interaction
P A S S I V E
Classification

Weaknesses

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79
  • Improper Control of Generation of Code ('Code Injection') CWE-94
Configurations

Affected products

1 configuration
Vulnerable match
cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:*
Through 2.1.15 inclusive
Further reading

References

6 sources
  1. github.com https://github.com/soerennb/extplorer/
  2. github.com https://github.com/soerennb/extplorer/commit/002def70b985f7012586df2c44368845bf405ab3 Patch
  3. github.com https://github.com/soerennb/extplorer/issues/33 Exploit Issue Tracking
  4. vuldb.com https://vuldb.com/?ctiid.332185 Permissions Required Vdb Entry
  5. vuldb.com https://vuldb.com/?id.332185 Third Party Advisory Us Government Resource
  6. vuldb.com https://vuldb.com/?submit.682370 Third Party Advisory Us Government Resource