CVE-2025-7618
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-14

Last updated on: 2025-07-15

Assigner: ASUSTOR, Inc.

Description
A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other sensitive information retained by the browser and used with the affected applications. Affected products and versions include: from ADM 4.1.0 to ADM 4.3.3.RH61 as well as ADM 5.0.0.RIN1 and earlier, and Text Editor 1.0.0.r112 and earlier.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-14
Last Modified
2025-07-15
Generated
2026-05-27
AI Q&A
2025-07-14
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
asustor text_editor 1.0.0.r112
asustor asustor_data_master 4.3.3.rh61
asustor asustor_data_master 4.1.0
asustor asustor_data_master 5.0.0.rin1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-7618 is a stored Cross-Site Scripting (XSS) vulnerability found in the File Explorer and Text Editor components of ASUSTOR Data Master (ADM). It allows an attacker to inject malicious scripts into these applications, which can then access browser cookies or other sensitive information used by the affected applications. [1]


How can this vulnerability impact me? :

This vulnerability can allow attackers to execute malicious scripts within the affected applications, potentially leading to unauthorized access to sensitive information such as browser cookies. This could result in compromised user sessions or data leakage. [1]


What immediate steps should I take to mitigate this vulnerability?

As of the advisory date, no fixed releases are available yet. Immediate mitigation steps include avoiding use of the affected ADM File Explorer and Text Editor versions (ADM 4.1.0 to 4.3.3.RH61, ADM 5.0.0.RIN1 and earlier, and Text Editor 1.0.0.r112 and earlier), limiting user privileges to reduce risk, and exercising caution with user interactions that could trigger the vulnerability. Monitoring official ASUSTOR advisories for patches or updates is also recommended. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart