CVE-2025-48162
7.1QuantumCloud · Simple Business Directory Pro
QuantumCloud Simple Business Directory Pro is vulnerable to reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation.
Executive summary
A reflected Cross-Site Scripting vulnerability in the QuantumCloud Simple Business Directory Pro plugin allows unauthenticated attackers to execute arbitrary scripts in the context of a user session.
Vulnerability
This is a reflected Cross-Site Scripting (CWE-79) flaw where the application fails to properly sanitize input. The vulnerability is exploitable by an unauthenticated attacker who can trick a user into interacting with a malicious link.
Business impact
The successful exploitation of this vulnerability can lead to session hijacking, unauthorized actions performed on behalf of the victim, and the theft of sensitive session cookies. Given the CVSS score of 7.1, this represents a significant security risk, as it compromises the integrity and confidentiality of the web application sessions for administrative or standard users.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should disable the plugin until the vendor releases a secure update.
Proactive Monitoring: Review web application logs for suspicious URL parameters containing script tags or encoded characters that deviate from expected input patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common XSS attack vectors to provide a virtual patch layer.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS severity rating, organizations should prioritize the removal or restriction of the Simple Business Directory Pro plugin until a confirmed fix is provided by QuantumCloud. Continuous monitoring of security advisories from the vendor is essential to ensure that a patched version is implemented as soon as it becomes available.
More QuantumCloud CVEs
Sources
Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.