CVE ID | CVE-2025-4379 |
Publication date | 23 May 2025 |
Vendor | Studio Fabryka |
Product | DobryCMS |
Vulnerable versions | 1.* and 2.* |
Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Studio Fabryka DobryCMS software and participated in coordination of its disclosure.
The vulnerability CVE-2025-4379: DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in szukaj parameter allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened.
A hotfix for affected versions was released on 29.04.2025. It removes the vulnerability without incrementing the version.
Credits
We thank Kamil Szczurowski and Robert Kruczek for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.