CVE-2025-29594 – Apache CS2-WeaponPaints Website Unvalidated Input XSS

CVE ID : CVE-2025-29594

Published : April 7, 2025, 8:15 p.m. | 1 hour, 5 minutes ago

Description : A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET[‘errorcode’] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…