216.73.216.197

CVE-2025-2597

· Published 21/03/2025 12:15 · Modified 21/03/2025 12:15

Labels: CVE-2025-2597 2025-03-21CVE-2025-2597CWE-79[email protected]

Essential information

Published
21/03/2025 12:15
Modified
21/03/2025 12:15
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET and POST requests to the ‘/index.php’ endpoint and injecting code into the ‘id_session.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
impact technologies / itium 6050 cpe:2.3:a:impact_technologies:itium_6050:5.5.5.2-b3526:*:*:*:*:*:*:*

References