CVE-2025-5990
15.06.2025, 18:15
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.
Vendor | Product | Version |
---|---|---|
craftycontrol | crafty_controller | 4.3.0 ≤ 𝑥 < 4.3.2 |
craftycontrol | crafty_controller | 4.4.0 ≤ 𝑥 < 4.4.10 |
craftycontrol | crafty_controller | 4.2.0 |
𝑥
= Vulnerable software versions