PT-2026-27211 · Census · Csweb

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2025-60948

CVSS v3.1

4.6

Medium

AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60948

Affected Products

Csweb