PT-2025-51274 · Unknown · Microstudio

Published

2025-12-15

·

Updated

2026-01-02

·

CVE-2025-51962

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MicroStudio version 24.01.29
Description A HTML Injection issue exists in the comment section of the project page. This allows remote attackers to inject arbitrary web script or HTML through the text parameter of the add project comment function.
Recommendations Apply updates to address the issue in the comment section of the project page. As a temporary workaround, consider disabling the add project comment function until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-51962

Affected Products

Microstudio