CVE Vulnerabilities

CVE-2025-4839

Origin Validation Error

Published: May 17, 2025 | Modified: Jun 04, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /paicoding-core/src/main/java/com/github/paicoding/forum/core/util/CrossUtil.java. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Paicoding Itwanger 1.0.0 (including) 1.0.0 (including)
Paicoding Itwanger 1.0.1 (including) 1.0.1 (including)
Paicoding Itwanger 1.0.2 (including) 1.0.2 (including)
Paicoding Itwanger 1.0.3 (including) 1.0.3 (including)

References