← back
CVE-2025-69245

Reflected XSS in Raytha CMS

CVSS 5.1 MEDIUMEPSS 0.3%CWE-79
Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue was fixed in 1.4.6.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Raytha · Raytha

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →