{"id":"CVE-2025-47204","aliases":["GHSA-gv5r-9gxr-v74w"],"url":"https://o3.security/vulnerability/CVE-2025-47204","summary":"Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data","details":"An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).","published":"2025-05-13T00:00:00Z","modified":"2026-08-12T03:51:33.789095696Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00438,"percentile":0.36317,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"bootstrap-multiselect","fixedVersion":"2.0.0"}],"fix":{"url":"https://github.com/projectdiscovery/nuclei-templates/commit/11e1a6c11d3954f44acfb0274b6dad4bd8045103","label":"projectdiscovery/nuclei-templates@11e1a6c"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47204.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47204"},{"type":"FIX","url":"https://github.com/projectdiscovery/nuclei-templates/commit/11e1a6c11d3954f44acfb0274b6dad4bd8045103"},{"type":"PACKAGE","url":"https://github.com/davidstutz/bootstrap-multiselect/releases"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.789095696Z"}}