CVE-2025-47204
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2025-47204. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.1Attack Vector Metrics
Impact Metrics
Description
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).
Available Exploits
Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting
A PHP script in the source code release echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).
References:
Related News
EU Vulnerability Database
Monitored by ENISA for EU cybersecurity
ENISA Analysis
Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
Affected Products (ENISA)
ENISA Scoring
EPSS Score
ENISA References
Data provided by ENISA EU Vulnerability Database. Last updated: May 15, 2025
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
GHSA-gv5r-9gxr-v74wAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Advisory provided by GitHub Security Advisory Database. Published: May 13, 2025, Modified: May 15, 2025