Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22056 | WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. |
Solution
Update AP to version 3.8.52.5 (Web 1.2.39.5) and install the hotfix, or update AP to version 3.9.1 (Web 1.3.1) or later
Workaround
No workaround given by the vendor.
Mon, 21 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Title | Simopro Technology|WinMatrix3 Web package - Reflected Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-07-21T15:25:35.826Z
Reserved: 2025-07-21T01:58:28.053Z
Link: CVE-2025-7920
Updated: 2025-07-21T15:25:12.399Z
Status : Awaiting Analysis
Published: 2025-07-21T07:15:25.137
Modified: 2025-07-22T13:06:07.260
Link: CVE-2025-7920
No data.
OpenCVE Enrichment
No data.
EUVD