CVE-2025-52180
EUVD-2025-3719330.10.2025, 19:16
Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahi/jsp/gsfr_feditorHTML.jsp?pHtmlSource endpoint.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zucchetti | ad_hoc_infinity | 𝑥 ≤ 4.2 |
𝑥
= Vulnerable software versions