PT-2025-38804 · Unknown · Ays Pro Poll Maker
Abu Hurayra
·
Published
2025-09-22
·
Updated
2025-09-22
·
CVE-2025-57954
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Ays Pro Poll Maker versions through 6.0.1
Description
Ays Pro Poll Maker is susceptible to a DOM-Based Cross-site Scripting issue due to improper input neutralization during web page generation. This allows for the injection of malicious scripts into web pages. The issue involves a vulnerability where untrusted data is incorporated into the Document Object Model (DOM) without proper sanitization, potentially leading to the execution of arbitrary JavaScript code in the context of the user's browser.
Recommendations
Update Ays Pro Poll Maker to a version later than 6.0.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ays Pro Poll Maker