HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'q' parameter in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
History

Tue, 29 Jul 2025 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Vox Media
Vox Media chorus Cms
Vendors & Products Vox Media
Vox Media chorus Cms

Mon, 28 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'q' parameter in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Title HTML injection in Vox Media's Chorus CMS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-07-28T10:28:30.800Z

Updated: 2025-07-28T15:18:50.377Z

Reserved: 2025-04-16T08:38:23.941Z

Link: CVE-2025-40730

cve-icon Vulnrichment

Updated: 2025-07-28T14:58:21.690Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-28T11:15:25.077

Modified: 2025-07-29T14:14:29.590

Link: CVE-2025-40730

cve-icon Redhat

No data.