<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>CVE-2025-12513</title><link>https://www.cvehunters.com/pt/p/cve-2025-12513/</link><description>Cross-Site Scripting (XSS) Armazenado</description><atom:link href="https://www.cvehunters.com/pt/p/cve-2025-12513/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-12513</title><link>https://www.cvehunters.com/pt/p/cve-2025-12513/</link><guid>https://www.cvehunters.com/pt/p/cve-2025-12513/</guid><description>&amp;lt;h2 id=&amp;#34;cve-2025-12513-cross-site-scripting-xss-armazenado&amp;#34;&amp;gt;CVE-2025-12513: Cross-Site Scripting (XSS) Armazenado
&amp;lt;/h2&amp;gt;&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;&amp;lt;strong&amp;gt;Publicação CVE: &amp;lt;a class=&amp;#34;link&amp;#34; href=&amp;#34;https://www.cve.org/CVERecord?id=CVE-2025-12513&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener&amp;#34;
&amp;gt;https://www.cve.org/CVERecord?id=CVE-2025-12513&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;h2 id=&amp;#34;resumo&amp;#34;&amp;gt;Resumo
&amp;lt;/h2&amp;gt;&amp;lt;p style=&amp;#34;text-align: justify;&amp;#34;&amp;gt;Um usuário com privilégios elevados pode injetar XSS na página de parâmetros de configuração do Host.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;impacto&amp;#34;&amp;gt;Impacto
&amp;lt;/h2&amp;gt;&amp;lt;p style=&amp;#34;text-align: justify;&amp;#34;&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Sequestro de sessão: Roubo de cookies ou tokens de autenticação para se passar por outros usuários.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Roubo de credenciais: Coleta de nomes de usuário e senhas usando scripts maliciosos.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Distribuição de malware: Distribuição de código indesejado ou prejudicial às vítimas.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Elevação de privilégios: Comprometimento de usuários administrativos por meio de scripts persistentes.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Manipulação ou adulteração de dados: Alteração ou interrupção do conteúdo do site.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Danos à reputação: Erosão da confiança entre usuários e administradores do site.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;/p&amp;gt;</description><content:encoded>&amp;lt;h2 id=&amp;#34;cve-2025-12513-cross-site-scripting-xss-armazenado&amp;#34;&amp;gt;CVE-2025-12513: Cross-Site Scripting (XSS) Armazenado
&amp;lt;/h2&amp;gt;&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;&amp;lt;strong&amp;gt;Publicação CVE: &amp;lt;a class=&amp;#34;link&amp;#34; href=&amp;#34;https://www.cve.org/CVERecord?id=CVE-2025-12513&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener&amp;#34;
&amp;gt;https://www.cve.org/CVERecord?id=CVE-2025-12513&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;
&amp;lt;h2 id=&amp;#34;resumo&amp;#34;&amp;gt;Resumo
&amp;lt;/h2&amp;gt;&amp;lt;p style=&amp;#34;text-align: justify;&amp;#34;&amp;gt;Um usuário com privilégios elevados pode injetar XSS na página de parâmetros de configuração do Host.&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;impacto&amp;#34;&amp;gt;Impacto
&amp;lt;/h2&amp;gt;&amp;lt;p style=&amp;#34;text-align: justify;&amp;#34;&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Sequestro de sessão: Roubo de cookies ou tokens de autenticação para se passar por outros usuários.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Roubo de credenciais: Coleta de nomes de usuário e senhas usando scripts maliciosos.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Distribuição de malware: Distribuição de código indesejado ou prejudicial às vítimas.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Elevação de privilégios: Comprometimento de usuários administrativos por meio de scripts persistentes.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Manipulação ou adulteração de dados: Alteração ou interrupção do conteúdo do site.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Danos à reputação: Erosão da confiança entre usuários e administradores do site.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;referência&amp;#34;&amp;gt;Referência
&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;a class=&amp;#34;link&amp;#34; href=&amp;#34;https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-12513-centreon-web-medium-severity-5360&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener&amp;#34;
&amp;gt;https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-12513-centreon-web-medium-severity-5360&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;h2 id=&amp;#34;encontrado-por&amp;#34;&amp;gt;Encontrado por:
&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&amp;lt;a class=&amp;#34;link&amp;#34; href=&amp;#34;http://www.linkedin.com/in/marceloqueirozjr&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener&amp;#34;
&amp;gt;&amp;lt;img src=&amp;#34;/assets/contributors/50x50/marcelo50x50.png&amp;#34;
loading=&amp;#34;lazy&amp;#34;
/&amp;gt;&amp;lt;/a&amp;gt; &amp;lt;a class=&amp;#34;link&amp;#34; href=&amp;#34;http://www.linkedin.com/in/marceloqueirozjr&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener&amp;#34;
&amp;gt;Marcelo Queiroz&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;em&amp;gt;&amp;lt;strong&amp;gt;By: &amp;lt;a class=&amp;#34;link&amp;#34; href=&amp;#34;https://github.com/CVE-Hunters/cve-hunters&amp;#34; target=&amp;#34;_blank&amp;#34; rel=&amp;#34;noopener&amp;#34;
&amp;gt;CVE-Hunters&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;&amp;lt;/em&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;/blockquote&amp;gt;</content:encoded><pubDate>Mon, 05 Jan 2026 00:00:00 +0000</pubDate></item></channel></rss>