First published: Fri Mar 21 2025(Updated: )
Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET and POST requests to the ‘/index.php’ endpoint and injecting code into the ‘id_session.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
ITIUM 6050 | ||
All of | ||
Itechno Itium 6050 Firmware | =5.5.5.2-b3526 | |
Itechno Itium 6050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2597 is rated as a medium severity vulnerability due to its potential to enable reflected cross-site scripting attacks.
Fixing CVE-2025-2597 involves validating and sanitizing user input on the affected '/index.php' endpoint.
CVE-2025-2597 is a reflected cross-site scripting (XSS) vulnerability.
CVE-2025-2597 affects ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies.
Yes, CVE-2025-2597 can be exploited remotely through crafted GET and POST requests.