A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try to access the infected codebox by clicking link or entering share code.
History

Mon, 24 Nov 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Lanol
Lanol filecodebox
CPEs cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:*
Vendors & Products Lanol
Lanol filecodebox

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Filecodebox
Filecodebox filecodebox
Vendors & Products Filecodebox
Filecodebox filecodebox

Thu, 20 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 20:00:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try to access the infected codebox by clicking link or entering share code.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-20T16:04:03.881Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51662

cve-icon Vulnrichment

Updated: 2025-11-20T16:03:11.144Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-19T20:15:53.017

Modified: 2025-11-24T19:40:24.100

Link: CVE-2025-51662

cve-icon Redhat

No data.