PT-2025-54440 · Unknown · Matamko En Masse
João Pedro S Alcântara
+1
·
Published
2025-12-31
·
Updated
2025-12-31
·
CVE-2025-23707
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Matamko En Masse versions through 1.0
Description
The software contains a flaw related to improper input handling during web page generation, which allows for Reflected Cross-site Scripting (XSS). This allows an attacker to inject malicious scripts into web pages viewed by other users. The vulnerable component does not properly sanitize user-supplied input before including it in the generated web page. This could allow an attacker to execute arbitrary JavaScript code in the context of the user's browser.
Recommendations
Versions prior to 1.0 should be updated.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matamko En Masse