CVE-2025-9590: Weaver E-Mobile Mobile Management Platform cross site scripting
A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerability is an unknown functionality. The manipulation of the argument gohome leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9590?
The severity of CVE-2025-9590 is assessed as high due to its potential for remote exploitation and cross site scripting.
How do I fix CVE-2025-9590?
To fix CVE-2025-9590, update the Weaver E-Mobile Mobile Management Platform to a version beyond 20250813.
What type of attack does CVE-2025-9590 facilitate?
CVE-2025-9590 facilitates cross site scripting (XSS) attacks.
Can CVE-2025-9590 be exploited remotely?
Yes, CVE-2025-9590 can be exploited remotely by manipulating the 'gohome' argument.
Which software is affected by CVE-2025-9590?
CVE-2025-9590 affects the Weaver E-Mobile Mobile Management Platform versions up to and including 20250813.