PT-2026-57053 · Myems · Myems
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MyEMS versions prior to 6.5.0
Description
An issue exists in the Admin Backend component within the
on post() function of the myems-api/core/svg.py file. Remote attackers can trigger cross-site scripting (XSS)—a technique used to inject malicious scripts into web pages viewed by other users—by manipulating the new values['data'] variable.Recommendations
Upgrade to version 6.5.0.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Myems