TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-10369

LOW
3.5

Description

A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Executing manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Details CVE

Score CVSS v3.13.5
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie9/13/2025
Derniere modification10/16/2025
Sourcenvd
Observations honeypot0

Produits affectes

sourcefabric:rpi-jukebox-rfid

Faiblesses (CWE)

CWE-79CWE-94CWE-79

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.