Stored Cross-Site Scripting Vulnerability in Pyxis Signage by Narkom Communication and Software Technologies Trade Ltd. Co.
CVE-2025-0643
7.2HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 20 November 2025
What is CVE-2025-0643?
A vulnerability has been identified in Pyxis Signage by Narkom Communication and Software Technologies Trade Ltd. Co., allowing for Stored Cross-Site Scripting (XSS) attacks. This flaw occurs due to improper handling of user input during the generation of web pages. Attackers could exploit this vulnerability to inject malicious scripts, which would be executed in the context of the user’s session. This poses a significant risk to users, potentially leading to unauthorized access and data leakage.
Affected Version(s)
Pyxis Signage 0 <= 31012025
