CVE-2025-25905

Publication date

2025-06-25 00:00:00

Family

mitre

State

PUBLISHED

Description

Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter.