PT-2026-5605 · Samsung · Magicinfo 9 Server
Published
2026-02-02
·
Updated
2026-03-10
·
CVE-2026-25200
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MagicINFO 9 Server versions prior to 21.1090.1
Description
A flaw exists in MagicINFO 9 Server that permits authorized users to upload HTML files without requiring authentication. This can lead to Stored Cross-Site Scripting (XSS), potentially resulting in account takeover. The issue involves the unauthorized upload of HTML files, which can then be exploited to inject malicious scripts.
Recommendations
Update MagicINFO 9 Server to version 21.1090.1 or later.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magicinfo 9 Server