PT-2026-27916 · Skygroup · Skygroup Sanzo

CVE-2026-25355

·

Published

2026-03-25

·

Updated

2026-03-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions skygroup Sanzo versions prior to 2.4.3
Description The software contains a flaw due to improper handling of user-supplied data when creating web pages, leading to a potential cross-site scripting (XSS) issue. Specifically, the vulnerability allows for stored XSS attacks. This means that malicious scripts can be injected into the application and stored, potentially affecting other users who access the compromised content.
Recommendations Update skygroup Sanzo to version 2.4.3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25355

Affected Products

Skygroup Sanzo