Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-63441 | Kitploit
Tools/GitHubGitHub/kgan0509/cve-2025-63441
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubkgan0509/cve-2025-63441

CVE-2025-63441

View Repository
9 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-63441

Title: Reflected XSS via arbitrarily supplied URL parameter param at endpoint u/administrator/friends

Summary: A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the u/administrator/friends endpoint of the OSSN application. This vulnerability allows attackers to inject malicious scripts the name of an arbitrarily supplied URL parameter.

Impact:

  • Perform virtual defacement of the web site.
  • Carry out any action that the user is able to perform.
  • Redirecting the user to a competing site.
  • Capture the user's(admin) session cookie.

Fixed in OSSN 8.7 and above github: https://github.com/opensource-socialnetwork/opensource-socialnetwork/issues/2501

PoC: Payload: ?tcjz4'>

Download Tool