PT-2026-7507 · Microcom · Zeusweb
Published
2026-02-11
·
Updated
2026-02-11
·
CVE-2025-13648
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZeusWeb version 6.1.31
Description
An attacker with access to the ZeusWeb web application could inject arbitrary JavaScript by exploiting a stored cross-site scripting (XSS) condition. The attack vector involves injecting an XSS payload into the
Name and Surname parameters within the ‘My Account’ section, accessible via the API endpoint 'https://zeus.microcom.es:4040/administracion-estaciones.html'.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize user input for the
Name and Surname parameters in the ‘My Account’ section to prevent the injection of malicious scripts.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zeusweb