CVE-2025-6700 | Xuxueli xxl-sso 1.1.0 /xxl-sso-server/login errorMsg cross site scripting (EUVD-2025-19213)
A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. Performing manipulation of the argument errorMsg results in cross site scripting.
This vulnerability is known as CVE-2025-6700. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.