Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potentially allowing attackers to inject malicious scripts that compromise the security and integrity of web applications. Applications based on this Bitplatform Boilerplate might also be vulnerable. Version 9.11.3 fixes the issue.
History

Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Bitfoundation
Bitfoundation bitplatform
Vendors & Products Bitfoundation
Bitfoundation bitplatform

Thu, 13 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 02:30:00 +0000

Type Values Removed Values Added
Description Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potentially allowing attackers to inject malicious scripts that compromise the security and integrity of web applications. Applications based on this Bitplatform Boilerplate might also be vulnerable. Version 9.11.3 fixes the issue.
Title Bitplatform Boilerplate has cross-site scripting vulnerability
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-13T01:40:55.653Z

Updated: 2025-11-13T14:35:03.575Z

Reserved: 2025-11-10T14:07:42.921Z

Link: CVE-2025-64710

cve-icon Vulnrichment

Updated: 2025-11-13T14:28:50.551Z

cve-icon NVD

Status : Received

Published: 2025-11-13T03:16:28.930

Modified: 2025-11-13T03:16:28.930

Link: CVE-2025-64710

cve-icon Redhat

No data.