PT-2025-39368 · Unknown · Nuz007 Smsboom
Dev03303
·
Published
2025-09-25
·
Updated
2025-09-25
·
CVE-2025-10946
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
nuz007 smsboom versions prior to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674
Description
A flaw exists in nuz007 smsboom. Manipulation of the
hm argument in an unknown function within the dy.php file can lead to cross site scripting. Remote exploitation is possible.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nuz007 Smsboom