CVE-2025-4379: Vulnerability Overview
On May 23, 2025, a new security vulnerability identified as CVE-2025-4379 was disclosed. This vulnerability is found in the Fabryka Dobrycms Software, impacting its versions 1. and 2.. The issue stems from inadequate input validation during web page generation, specifically relating to Cross-Site Scripting (XSS) vulnerabilities, categorized as CWE-79.
Vulnerability Details
The relevant input parameter, Szukaj, allows for the execution of arbitrary JavaScript in a user’s browser when a specially crafted URL is accessed. This exposes users to potential malicious activities such as data theft or session hijacking, highlighting the critical nature of XSS vulnerabilities in web applications.
CERT Polska received the report regarding this vulnerability and played a role in coordinating its public disclosure. Following the identification of the vulnerability, a hotfix was promptly released on April 29, 2025, aimed at mitigating the risk associated with the flaw. This fix effectively addresses the issue while keeping the affected versions unchanged, ensuring that users can secure their systems without the need for major updates.
Responsibility and Coordination
The investigation and subsequent disclosure of CVE-2025-4379 were facilitated by responsible researchers Kamil Szczurowski and Robert Kruczek, who reported the vulnerability. Their proactive approach in notifying the relevant parties allowed for a swift response, showcasing the importance of collaboration in enhancing software security.
User Recommendations
Users of Fabryka Dobrycms Software are urged to update their systems immediately to mitigate the risk associated with this vulnerability. Since the hotfix was designated to address the issue directly, applying it will protect users from potential XSS attacks that could compromise their data and privacy.
For further insights into the coordinated vulnerability disclosure processes, users can explore resources available through CERT Polska.
In summary, CVE-2025-4379 presents a significant risk for users of specific versions of the Fabryka Dobrycms Software due to its vulnerability to cross-site scripting attacks. The timely response from CERT Polska and the researchers involved has enabled a quick resolution to the matter, emphasizing the need for ongoing vigilance in software security practices.