PT-2025-37372 · Miczflor · Rpi-Jukebox-Rfid

Xu17

·

Published

2025-09-13

·

Updated

2025-09-13

·

CVE-2025-10366

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: MiczFlor RPi-Jukebox-RFID versions up to 2.8.0
Description: A flaw has been found in MiczFlor RPi-Jukebox-RFID. The manipulation of the Email address argument in an unknown function of the file /htdocs/inc.setWlanIpMail.php causes cross site scripting. The attack may be initiated remotely.
Recommendations: Versions prior to 2.8.0 should be updated. As a temporary workaround, consider restricting access to the /htdocs/inc.setWlanIpMail.php file until a patch is available.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-10366

Affected Products

Rpi-Jukebox-Rfid