CVE-2025-64130: Zenitel TCIV-3+ Cross-site Scripting
Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64130?
CVE-2025-64130 is considered a medium severity vulnerability due to its potential to allow remote code execution via reflected cross-site scripting.
How do I fix CVE-2025-64130?
To fix CVE-2025-64130, it is recommended to update Zenitel TCIV-3+ to version 9.3.3.1 or later.
Who is affected by CVE-2025-64130?
Organizations using Zenitel TCIV-3+ versions up to and including 9.3.3.0 are affected by CVE-2025-64130.
What is the impact of CVE-2025-64130?
The impact of CVE-2025-64130 allows attackers to execute arbitrary JavaScript in the context of the victim's browser, leading to potential data theft or session hijacking.
What type of vulnerability is CVE-2025-64130?
CVE-2025-64130 is classified as a reflected cross-site scripting (XSS) vulnerability.