{"id":"CVE-2025-10944","summary":"yi-ge get-header-ip ip.php cross site scripting","details":"A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects the function ip of the file ip.php. This manipulation of the argument callback causes cross site scripting. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.","modified":"2026-10-08T02:48:56.533854740Z","published":"2025-09-25T12:32:06.378Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-79","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10944.json"},"references":[{"type":"WEB","url":"https://github.com/yi-ge/get-header-ip/blob/master/ip.php#L32"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10944.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10944"},{"type":"ADVISORY","url":"https://vuldb.com/?id.325814"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.651884"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.325814"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yi-ge/get-header-ip","events":[{"introduced":"589b23d0eb0043c310a6a13ce4bbe2505d0d0b15"},{"last_affected":"589b23d0eb0043c310a6a13ce4bbe2505d0d0b15"}]}],"versions":["589b23d0eb0043c310a6a13ce4bbe2505d0d0b15"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10944.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"}]}