← Back

CVE-2025-13648

nvd nist
Published: Feb 11, 2026Modified: Mar 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ffb98d57-deaa-4918-a669-5225ccc13e39 (Secondary)

Description

An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is required) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Name’ and “Surname” parameters within the ‘My Account’ section at the URL: https://zeus.microcom.es:4040/administracion-estaciones.html  resulting in a stored XSS. This issue affects ZeusWeb: 6.1.31.

Affected (1)

Products: Microcom360: Zeusweb
1 product
Zeusweb
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.1.31

References (4)

Source: ffb98d57-deaa-4918-a669-5225ccc13e39
Third Party Advisory
Source: ffb98d57-deaa-4918-a669-5225ccc13e39
Third Party Advisory
Source: ffb98d57-deaa-4918-a669-5225ccc13e39
Product
Source: ffb98d57-deaa-4918-a669-5225ccc13e39
Permissions Required

Timeline

No history available yet.