PT-2026-7508 · Microcom · Zeusweb
Published
2026-02-11
·
Updated
2026-02-11
·
CVE-2025-13649
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZeusWeb version 6.1.31
Description
An attacker with access to the web application ZeusWeb could inject arbitrary JavaScript by exploiting a cross-site scripting (XSS) issue. The attack vector involves injecting an XSS payload into the ‘Email’ parameters within the ‘Recover password’ section at the API endpoint 'https://zeus.microcom.es:4040/index.html?zeus6=true'. The vulnerable parameter is
Email.Recommendations
Update ZeusWeb to a newer version that addresses this issue. As a temporary workaround, sanitize user input for the
Email parameter in the ‘Recover password’ section to prevent the injection of malicious scripts.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zeusweb