CVE-2025-7618 describes a stored Cross-Site Scripting (XSS) vulnerability in the File Explorer and Text Editor components of ADM, affecting versions from ADM 4.1.0 to 4.3.3.RH61, ADM 5.0.0.RIN1 and earlier, and Text Editor 1.0.0.r112 and earlier. An attacker with low privileges could exploit this by injecting malicious scripts, potentially leading to unauthorized access of sensitive user data. The vulnerability has a CVSS score of 4.8 (Medium), indicating a network attack vector with low attack complexity and impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.0, <= 4.3.3.RH61CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.0.0.RIN1CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 1.0.0, <= 1.0.0.r112CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.