PT-2025-39857 · Unknown · Mycourts V3
Published
2025-09-29
·
Updated
2025-12-23
·
CVE-2025-57424
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MyCourts version 3
Description
A stored cross-site scripting (XSS) issue exists in the LTA number profile field of the MyCourts v3 application. An attacker can inject arbitrary JavaScript code into their profile. This code will then execute in the browsers of users who view the profile, potentially including administrators. The lack of the HttpOnly flag on the session cookie could allow an attacker to capture session tokens and hijack user sessions, leading to elevated access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mycourts V3