PT-2025-41257 · Unknown · Configuroweb Sistema Web De Inventario

Chuckbartowski7

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-60314

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Configuroweb Sistema Web de Inventario version 1.0
Description The software is susceptible to a Stored Cross-Site Scripting (XSS) issue because of insufficient input sanitization. Specifically, the Nombre:Producto parameter lacks proper validation, enabling an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript. The affected parameter is the product name.
Recommendations Apply input sanitization to the Nombre:Producto parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60314

Affected Products

Configuroweb Sistema Web De Inventario