PT-2025-39857 · Unknown · Mycourts V3

Published

2025-09-29

·

Updated

2025-12-23

·

CVE-2025-57424

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MyCourts version 3
Description A stored cross-site scripting (XSS) issue exists in the LTA number profile field of the MyCourts v3 application. An attacker can inject arbitrary JavaScript code into their profile. This code will then execute in the browsers of users who view the profile, potentially including administrators. The lack of the HttpOnly flag on the session cookie could allow an attacker to capture session tokens and hijack user sessions, leading to elevated access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57424

Affected Products

Mycourts V3