CVE-2025-25477
28.02.2025, 00:15
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.
Awaiting analysis
This vulnerability is currently awaiting analysis.