CVE-2025-4674

Published Jul 29, 2025

Last updated 2 months ago

CVSS high 8.6
CampCodes

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-46746 refers to a vulnerability where an administrator could discover another account's credentials. CVE-2024-4674, a different vulnerability, was found in Campcodes Complete Web-Based School Management System 1.0. It affects the `/view/show_friend_request.php` file, where manipulation of the `my_index` argument leads to cross-site scripting. The exploit is public and can be initiated remotely.

Description
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.
Source
security@golang.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.6
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-73

Social media

Hype score
Not currently trending