CVE-2025-63229
PoC —CVSS 3.1
5.4 medium
EPSS
<1%p20
Published
()
Modified
Description
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious JavaScript payload into the ?m= query parameter, an attacker can execute arbitrary code in the victim's browser, potentially stealing sensitive information, hijacking sessions, or performing unauthorized actions.
- Vendors
- dbbroadcast
- Products
- mozart next 100 firmware, mozart next 1000 firmware, mozart next 2000 firmware, mozart next 30 firmware, mozart next 300 firmware, mozart next 3000 firmware, mozart next 3500 firmware, mozart next 50 firmware, mozart next 500 firmware, mozart next 6000 firmware, mozart next 7000 firmware, mozart dds next 30 firmware
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.