5.4
CVE-2025-63229
- EPSS 0.06%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 06.12.2025 00:18:19
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious JavaScript payload into the ?m= query parameter, an attacker can execute arbitrary code in the victim's browser, potentially stealing sensitive information, hijacking sessions, or performing unauthorized actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dbbroadcast ≫ Mozart Next 100 Firmware Version-
Dbbroadcast ≫ Mozart Next 1000 Firmware Version-
Dbbroadcast ≫ Mozart Next 2000 Firmware Version-
Dbbroadcast ≫ Mozart Next 30 Firmware Version-
Dbbroadcast ≫ Mozart Next 300 Firmware Version-
Dbbroadcast ≫ Mozart Next 3000 Firmware Version-
Dbbroadcast ≫ Mozart Next 3500 Firmware Version-
Dbbroadcast ≫ Mozart Next 50 Firmware Version-
Dbbroadcast ≫ Mozart Next 500 Firmware Version-
Dbbroadcast ≫ Mozart Next 6000 Firmware Version-
Dbbroadcast ≫ Mozart Next 7000 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 30 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 50 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 100 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 300 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 500 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 1000 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 2000 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 3000 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 3500 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 6000 Firmware Version-
Dbbroadcast ≫ Mozart Dds Next 7000 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.196 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.