PT-2025-38804 · Unknown · Ays Pro Poll Maker

Abu Hurayra

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-57954

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ays Pro Poll Maker versions through 6.0.1
Description Ays Pro Poll Maker is susceptible to a DOM-Based Cross-site Scripting issue due to improper input neutralization during web page generation. This allows for the injection of malicious scripts into web pages. The issue involves a vulnerability where untrusted data is incorporated into the Document Object Model (DOM) without proper sanitization, potentially leading to the execution of arbitrary JavaScript code in the context of the user's browser.
Recommendations Update Ays Pro Poll Maker to a version later than 6.0.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57954

Affected Products

Ays Pro Poll Maker