CVE-2025-47204 describes a Reflective Cross-Site Scripting (XSS) vulnerability in bootstrap-multiselect version 1.1.2, specifically within the post.php component, affecting the davidstutz bootstrap_multiselect product. This medium-severity vulnerability (CVSS 6.1) arises from the script echoing arbitrary POST data, allowing an attacker to inject malicious scripts if a developer integrates this structure into a live application. Exploitation requires user interaction via Cross-Site Request Forgery (CSRF) and could lead to low impact on confidentiality and integrity. There is no evidence of active exploitation, no Metasploit or ExploitDB modules, but Nuclei templates exist, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2CPE matchmatch criteria | cpe:2.3:a:davidstutz:bootstrap_multiselect:1.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.