PT-2025-54187 · Webcreations907 · Webcreations907 Wbc907 Core
João Pedro S Alcântara
+1
·
Published
2025-12-30
·
Updated
2025-12-30
·
CVE-2025-63027
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Webcreations907 WBC907 Core versions through 3.4.1
Description
The software contains a flaw due to improper neutralization of input during web page generation, leading to a Cross-site Scripting (XSS) issue. This specific instance allows for Stored XSS attacks. The issue impacts the way user-supplied data is handled when creating web pages, potentially allowing malicious scripts to be injected and executed in the context of other users' browsers. The vulnerable component is susceptible to attacks where an attacker can inject malicious code into the application, which is then stored and served to other users.
Recommendations
Update Webcreations907 WBC907 Core to a version later than 3.4.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webcreations907 Wbc907 Core