CVE-2025-14801 | xiweicheng TMS up to 2.28.0 create createComment content cross site scripting (EUVD-2025-203862)
A vulnerability classified as problematic was found in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting.
This vulnerability is listed as CVE-2025-14801. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.