← Back

CVE-2025-1271

nvd nist
Published: Feb 13, 2025Modified: Jan 29, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: cve-coordination@incibe.es (Secondary)

Description

Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a user accesses that URL, the injected code is executed in their browser, which can result in the theft of sensitive information, identity theft or the execution of unauthorised actions on behalf of the affected user.

Affected (1)

Products: Anapi: H6web
1 product
H6web
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (1)

Timeline

No history available yet.