7.3
CVE-2025-55618
- EPSS 0.05%
- Veröffentlicht 27.08.2025 20:15:33
- Zuletzt bearbeitet 09.09.2025 15:08:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hyundai ≫ Navigation Versionstd5w.eur.hmc.230516.afa908d
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.148 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.