PT-2025-50047 · Averta · Master Slider Pro
Published
2025-12-09
·
Updated
2025-12-09
·
CVE-2025-63045
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Master Slider Pro versions prior to 3.7.13
Description
Improper neutralization of input during web page generation in the masterslider component allows for DOM-Based Cross-site Scripting (XSS), a flaw where an application contains client-side JavaScript that processes data from an untrusted source in an unsafe way, typically updating the Document Object Model (DOM).
Recommendations
Update to a version newer than 3.7.12.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Master Slider Pro