PT-2025-54440 · Unknown · Matamko En Masse

João Pedro S Alcântara

+1

·

Published

2025-12-31

·

Updated

2025-12-31

·

CVE-2025-23707

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Matamko En Masse versions through 1.0
Description The software contains a flaw related to improper input handling during web page generation, which allows for Reflected Cross-site Scripting (XSS). This allows an attacker to inject malicious scripts into web pages viewed by other users. The vulnerable component does not properly sanitize user-supplied input before including it in the generated web page. This could allow an attacker to execute arbitrary JavaScript code in the context of the user's browser.
Recommendations Versions prior to 1.0 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-23707

Affected Products

Matamko En Masse