5.4
CVSSv3

CVE-2025-2699

CVSSv4: 5.1 | CVSSv3: 5.4 | CVSSv2: 4 | VMScore: 610 | EPSS: 0.00042 | KEV: Not Included
Published: 24/03/2025 Updated: 24/03/2025

Vulnerability Summary

Cross-Site Scripting in GetmeUK ContentTools via Image Handler Argument

A cross site scripting vulnerability exists in GetmeUK ContentTools up to version 1.6.16 within the Image Handler component. The vulnerability can be triggered remotely through manipulation of the onload argument. The issue has been publicly disclosed and potentially usable by attackers. The vulnerability has been rated as problematic, and despite early notification, the vendor did not provide a response to the security disclosure.

Vulnerable Product Search on Vulmon Subscribe to Product

getmeuk contenttools

getcontenttools contenttools