Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.
Version 5.20 of MegaBIP fixes this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 23 May 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 May 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required. Version 5.20 of MegaBIP fixes this issue. | |
Title | Stored XSS in MegaBIP | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-05-23T10:20:03.081Z
Updated: 2025-05-23T12:12:19.666Z
Reserved: 2025-04-23T09:52:15.268Z
Link: CVE-2025-3894

Updated: 2025-05-23T12:12:14.644Z

Status : Awaiting Analysis
Published: 2025-05-23T11:15:32.820
Modified: 2025-05-23T15:54:42.643
Link: CVE-2025-3894

No data.