
Proof-of-concept for CVE-2025-60654: stored cross-site scripting (XSS) in Script Pag ad description field. Demonstrates filter bypass using HTML tags like <img src=x onerror=alert('XSS')>.
| Researchers | DotAdrien |
| Severity | 7.2 (HIGH) (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N) |
| Software | Script Pag |
The ad description field is vulnerable to stored Cross-Site Scripting (XSS). Although some security filters are in place, they can be easily bypassed using standard HTML tags. For example, using `` allows an attacker to execute JavaScript in the browser of anyone viewing the specific pages.