PT-2025-48938 · Avtech Security · Dgm1104
Published
2025-12-03
·
Updated
2025-12-03
·
CVE-2025-57202
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003
Description
A stored cross-site scripting (XSS) issue exists in the
PwdGrp.cgi endpoint. Attackers can inject a crafted payload into the username field, potentially leading to the execution of arbitrary web scripts or HTML.Recommendations
Sanitize user input for the
username field in the PwdGrp.cgi endpoint to prevent the injection of malicious scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dgm1104