PT-2026-6736 · Lolypop55 · Html5 Snmp

Cakes

·

Published

2026-02-06

·

Updated

2026-03-02

·

CVE-2019-25294

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions html5 snmp version 1.11
Description The software contains a persistent cross-site scripting issue. An attacker can inject malicious scripts through the Remark parameter in the add router operation.php file. By crafting a POST request with a script payload in the Remark field, an attacker can execute arbitrary JavaScript in the browsers of those who view the page. The vulnerable parameter is Remark. The affected file is add router operation.php.
Recommendations Apply a fix to the add router operation.php file to sanitize the Remark parameter and prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25294

Affected Products

Html5 Snmp