Junglewise Threat Intelligence

CVE-2025-7885: Huashengdun WebSSH cross-site scripting in login page

CVE-2025-7885 · Severity: medium · CVSS 4.3 · Published 2025-07-20

Vendors: PyPI.

Executive brief

Huashengdun WebSSH is a web-based terminal emulator that allows users to access SSH servers through a browser. A security flaw in the login page allows attackers to inject malicious scripts into the application by tricking a user into clicking a specially crafted link. If successful, an attacker could perform unauthorized actions in the user's browser session, such as stealing session information or redirecting the user to malicious websites.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Huashengdun WebSSH versions prior to 1.6.3. The application fails to properly sanitize or encode user-supplied input provided via the 'hostname' and 'port' GET parameters on the login page before reflecting them in the HTML response. A remote attacker can exploit this by enticing a user to visit a malicious URL containing a JavaScript payload. Successful exploitation allows for the execution of arbitrary script code in the context of the victim's browser session. The issue was addressed in version 1.6.3.

Affected products

  • Huashengdun WebSSH < 1.6.3

Timeline

  • 2025-04-09: disclosed: Vulnerability reported via GitHub issue and PoC published.
  • 2025-07-20: advisory: GitHub and NVD advisories published.
  • 2025-07-20: patched: Version 1.6.3 released to address the issue.

References