CVE-2025-7803 is a Cross-Site Scripting (XSS) vulnerability found in the validToken function of the /wx.php file within descreekert wx-discuz, affecting versions up to commit 12bd4745c63ec203cb32119bf77ead4a923bf277. This vulnerability allows for remote attacks by manipulating the 'echostr' argument. Rated with a CVSS score of 3.5 (LOW), the vulnerability requires low privileges and user interaction, with a potential impact of low integrity. The attack vector is network-based, but the overall severity is considered low. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage are minimal, indicating a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Descreekert | Wx-Discuz | 12bd4745c63ec203cb32119bf77ead4a923bf277CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.