PT-2026-5605 · Samsung · Magicinfo 9 Server
CVE-2026-25200
·
Publicado
2026-02-02
·
Atualizado
2026-03-10
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MagicINFO 9 Server versions prior to 21.1090.1
Description
A flaw exists in MagicINFO 9 Server that permits authorized users to upload HTML files without requiring authentication. This can lead to Stored Cross-Site Scripting (XSS), potentially resulting in account takeover. The issue involves the unauthorized upload of HTML files, which can then be exploited to inject malicious scripts.
Recommendations
Update MagicINFO 9 Server to version 21.1090.1 or later.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Magicinfo 9 Server