CVE-2025-36558: KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the ssotoken used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an ssotoken, that script will reply to the user and be executed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36558?
CVE-2025-36558 is considered a critical vulnerability due to the potential for cross-site scripting attacks affecting authentication.
How do I fix CVE-2025-36558?
To fix CVE-2025-36558, upgrade to KUNBUS PiCtory version 2.11.2 or later which contains the necessary security patches.
What type of attack is associated with CVE-2025-36558?
CVE-2025-36558 is associated with a cross-site scripting (XSS) attack via a malicious sso_token in PiCtory URLs.
Who is affected by CVE-2025-36558?
CVE-2025-36558 affects users utilizing KUNBUS PiCtory versions 2.11.1 and earlier across critical infrastructure sectors.
Where can I find more information about CVE-2025-36558?
Further information on CVE-2025-36558 can be found in official advisories from CISA and MITRE.