Metrics
Affected Vendors & Products
Solution
Update AP to version 3.8.52.5 (Web 1.2.39.5) and install the hotfix, or update AP to version 3.9.1 (Web 1.3.1) or later
Workaround
No workaround given by the vendor.
Mon, 21 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
Title | Simopro Technology|WinMatrix3 Web package - Reflected Cross-Site Scripting | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-07-21T15:25:35.826Z
Reserved: 2025-07-21T01:58:28.053Z
Link: CVE-2025-7920

Updated: 2025-07-21T15:25:12.399Z

Status : Awaiting Analysis
Published: 2025-07-21T07:15:25.137
Modified: 2025-07-22T13:06:07.260
Link: CVE-2025-7920

No data.

No data.