Version 5.20 of MegaBIP fixes this issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27941 | Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required. Version 5.20 of MegaBIP fixes this issue. |
Fri, 23 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required. Version 5.20 of MegaBIP fixes this issue. | |
| Title | Stored XSS in MegaBIP | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-05-23T12:12:19.666Z
Reserved: 2025-04-23T09:52:15.268Z
Link: CVE-2025-3894
Updated: 2025-05-23T12:12:14.644Z
Status : Deferred
Published: 2025-05-23T11:15:32.820
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-3894
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD