The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 0.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 0.00 |
VPI formula vpi-v1