PT-2025-54400 · Elinicksic+1 · Razgover

CVE-2019-25262

·

Published

2025-12-31

·

Updated

2025-12-31

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions elinicksic Razgover versions prior to 995dd89d0e3ec5522966724be23a5d58ca1bdac3
Description A remote cross-site scripting issue exists in the Chat Message Handler component within the 'Chattify/send.php' file. The flaw allows a remote attacker to execute malicious scripts by manipulating the msg argument.
Recommendations Apply patch 995dd89d0e3ec5522966724be23a5d58ca1bdac3 to resolve the issue.

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25262

Affected Products

Razgover