Report: CVE-2018-25349 - userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header - Analysis

Report: CVE-2018-25349 - userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header - Analysis

CVE ID :CVE-2018-25349 Published : May 23, 2026, 6:30 p.m. | 1 hour, 50 minutes ago Description :userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log page. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 23, 2026
Affected Product: php
Impact: XSS