PT-2025-13528 · Unknown · Satech Bcu

Aarón Flecha

·

Published

2025-03-28

·

Updated

2025-03-28

·

CVE-2025-2865

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SaTECH BCU version 2.1.3
Description The issue allows XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users, causing them to interpret the code stored on another malicious website owned by the attacker.
Recommendations For SaTECH BCU version 2.1.3, consider restricting access to the web server to minimize the risk of exploitation. As a temporary workaround, avoid using the web application until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2865

Affected Products

Satech Bcu