PT-2025-54419 · Unknown · Stvs Provision

Published

2025-12-31

·

Updated

2025-12-31

·

CVE-2021-47725

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions STVS ProVision version 5.9.10
Description The software contains a cross-site scripting issue in the 'files' POST parameter. Authenticated attackers can inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site. The vulnerable parameter is files.
Recommendations Apply input validation and sanitization to the files POST parameter to prevent the injection of malicious HTML code.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47725

Affected Products

Stvs Provision