PT-2026-27916 · Skygroup · Skygroup Sanzo

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-25355

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions skygroup Sanzo versions prior to 2.4.3
Description The software contains a flaw due to improper handling of user-supplied data when creating web pages, leading to a potential cross-site scripting (XSS) issue. Specifically, the vulnerability allows for stored XSS attacks. This means that malicious scripts can be injected into the application and stored, potentially affecting other users who access the compromised content.
Recommendations Update skygroup Sanzo to version 2.4.3 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-25355

Affected Products

Skygroup Sanzo