PT-2025-37912 · Ubit Information Technologies · Stoys

Published

2025-09-16

·

Updated

2025-09-19

·

CVE-2025-2404

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ubit Information Technologies STOYS versions 2 through 20250916
Description The software contains an Improper Neutralization of Input During Web Page Generation vulnerability, which allows for Cross-Site Scripting (XSS). The vendor has not yet confirmed the completion of the fixing process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-2404

Affected Products

Stoys