CVE-2024-58285 PUBLISHED

Chyrp 2.5.2 Stored Cross-Site Scripting Vulnerability via Post Title

Assigner: VulnCheck
Reserved: 10.12.2025 Published: 10.12.2025 Updated: 11.12.2025

Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing client-side attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.3

Product Status

Vendor chyrp
Product Chyrp
Versions Default: unaffected
  • Version 2.5.2 is affected

Credits

  • Ahmet Ümit BAYRAM finder

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE