CVE-2023-25295: Gruen EVEWA3

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel.

Affected products

  • Gruen EVEWA3: from 31, up to and including 53

Published 2024-01-17. Last modified 2026-06-17.