Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-56313

EPSS 0.04% · P12
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-56313

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary JavaScript in a user's web browser by including a malicious payload in the "code" URL parameter. When an authenticated admin user accesses the study's URL, the malicious script gets interpreted and executes within their browser, which can lead to unauthorized actions, account compromise, and privilege escalation.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
JATOS 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
JATOS是JATOS开源的一个在线学习工具。 JATOS 3.7.1版本至3.9.6版本存在安全漏洞,该漏洞源于/publix/run端点中code参数未正确过滤,可能导致反射型跨站脚本攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-56313

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-56313

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-10-30 · 26 CVEs total

CVE-2025-61121Glority Limited Mobile Scanner Android App 安全漏洞
CVE-2025-61498Tenda AC8 安全漏洞
CVE-2025-61141sqls 安全漏洞
CVE-2025-52180Zucchetti Ad Hoc Infinity 安全漏洞
CVE-2025-52179Zucchetti Ad Hoc Revolution 安全漏洞
CVE-2025-63422Each Italy Wireless Mini Router WIRELESS-N 300M 安全漏洞
CVE-2025-63298SourceCodester Pet Grooming Management System 安全漏洞
CVE-2025-63423Each Italy Wireless Mini Router WIRELESS-N 300M 安全漏洞
CVE-2025-57109Kitware VTK 安全漏洞
CVE-2025-61120IOFIT AG Life Logger Android App 安全漏洞
CVE-2025-61119Kanova Android App 安全漏洞
CVE-2025-61114AutoBizLine 2nd Line Android App 安全漏洞
CVE-2025-61118mCarFix Motorists App 安全漏洞
CVE-2025-63608CSZ-CMS 安全漏洞
CVE-2025-61196BusinessNext CRMnext 安全漏洞
CVE-2025-61117Senza: Keto & Fasting 安全漏洞
CVE-2025-63885AIxBlock 安全漏洞
CVE-2025-60950AIxBlock 安全漏洞
CVE-2025-60319PerfreeBlog 安全漏洞
CVE-2025-61116AdForest – Classified Android App 安全漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-56313

No comments yet


Leave a comment