Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29096 | A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 17 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcefabric rpi-jukebox-rfid
|
|
| CPEs | cpe:2.3:a:sourcefabric:rpi-jukebox-rfid:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sourcefabric rpi-jukebox-rfid
|
Mon, 15 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcefabric
Sourcefabric phoniebox |
|
| Vendors & Products |
Sourcefabric
Sourcefabric phoniebox |
Sat, 13 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | MiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-15T15:39:17.314Z
Reserved: 2025-09-12T14:04:41.831Z
Link: CVE-2025-10370
Updated: 2025-09-15T15:39:13.775Z
Status : Analyzed
Published: 2025-09-13T17:15:31.693
Modified: 2025-10-17T19:17:20.507
Link: CVE-2025-10370
No data.
OpenCVE Enrichment
Updated: 2025-09-15T10:43:34Z
EUVD