Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-52097 — Public Disclosure of CVE-2025-52097 | Kitploit
Tools/GitHubGitHub/rwilsonecs/cve-2025-52097
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubrwilsonecs/cve-2025-52097

CVE-2025-52097

Public Disclosure of CVE-2025-52097

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-52097 – Reflected XSS in InstantForum.NET v4.1.4

This repository contains the public advisory, proof of concept, and supporting materials for CVE-2025-52097, a reflected cross-site scripting (XSS) vulnerability identified in InstantForum.NET v4.1.4.

Summary

Product: InstantForum.NET v4.1.4
Vendor: InstantASP Ltd. (no longer in operation)
Vulnerability Type: Reflected Cross-Site Scripting (XSS)

Description:
Un-sanitized input in the hbhxg query string parameter is reflected directly into the HTML response without output encoding, allowing an attacker to execute arbitrary JavaScript in the victim's browser without authentication.

Advisory

Full technical advisory, including exploitation details and remediation recommendations, is available in ADVISORY.md.

Proof of Concept

Proof of concept screenshots are included in this repository:

  • poc_proof.png – Payload execution
  • poc_proof_2.png – Reflection and version confirmation

Disclosure

  • Discoverer: Ryan Wilson, ECS MSP ARC Red Team
  • CVE ID: CVE-2025-52097
  • Date Advisory Published: July 11, 2025

License

This advisory is provided for educational and defensive security purposes only.


For questions regarding this disclosure, please contact [email protected].

Download Tool