PT-2025-7845 · Estatik · Estatik Mortgage Calculator

João Pedro S Alcântara

·

Published

2025-02-25

·

Updated

2025-02-25

·

CVE-2025-26907

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mortgage Calculator Estatik versions n/a through 2.0.12
Description The issue is related to improper neutralization of input during web page generation, which leads to a Cross-site Scripting (XSS) vulnerability. Specifically, it is a Stored XSS vulnerability, meaning the malicious script is stored on the server and executed when a user accesses the affected page.
Recommendations For Mortgage Calculator Estatik versions n/a through 2.0.12, update to a version later than 2.0.12 to resolve the issue. As a temporary workaround, consider restricting user input to prevent malicious scripts from being stored and executed.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-26907

Affected Products

Estatik Mortgage Calculator