CVE-2025-51662

A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try to access the infected codebox by clicking link or entering share code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-19 20:15

Updated : 2025-11-24 19:40


NVD link : CVE-2025-51662

Mitre link : CVE-2025-51662

CVE.ORG link : CVE-2025-51662


JSON object : View

Products Affected

lanol

  • filecodebox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')