PT-2025-48112 · Db Elettronica Telecomunicazioni Spa · Mozart Fm Transmitter

Abdul Mhanni

·

Published

2025-11-26

·

Updated

2025-11-26

·

CVE-2025-66258

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30 through 7000
Description The software contains a Stored Cross-Site Scripting issue due to XML Injection. An attacker can execute malicious JavaScript payloads by injecting crafted filenames into the patchlist.xml file. User-controlled filenames are directly concatenated into patchlist.xml without encoding. The XSS executes when the ajax.js file processes and renders the XML file. The vulnerable parameter is the filename.
Recommendations Versions 30 through 7000 should be updated to a newer version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66258

Affected Products

Mozart Fm Transmitter