ROBERT KRUCZEK
← Back to home

CVE-2025-3894

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVSS v4.0: 4.8 (MEDIUM) Published: May 23, 2025 View on NVD →

Description

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.  
Version 5.20 of MegaBIP fixes this issue.

Affected Products

Vendor Product Versions Affected
Jan Syski MegaBIP 0 (<= 5.19) (affected)

CVSS Score & Vector

Base Score: 4.8 (MEDIUM)
Vector (v4.0):
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Credits / Discoverer

  • Kamil Szczurowski
  • Robert Kruczek