Junglewise Threat Intelligence

CVE-2025-9035: Horato Virtual Library Platform Reflected XSS

CVE-2025-9035 · Severity: medium · CVSS 5.4 · Published 2025-09-22

Executive brief

A security vulnerability exists in the Horato Virtual Library Platform, a system used for managing digital library resources. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's web browser. This could lead to the theft of session information or unauthorized actions performed on behalf of the user within the library system.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Horato Internet Technologies Virtual Library Platform before version v202. The application fails to properly neutralize user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The vulnerability has been addressed in version v202.

Affected products

  • Horato Internet Technologies Ind. And Trade Inc. Virtual Library Platform before v202

Timeline

  • 2025-09-22: disclosed
  • 2025-09-22: advisory

References