CVE-2025-10485: Pojoin h3blog
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the component HTTP Header Handler. Such manipulation of the argument X-Forwarded-For leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
Affected products
- Pojoin h3blog
Published 2025-09-15. Last modified 2026-06-17.