Cross-Site Scripting Flaw in MiczFlor RPi-Jukebox-RFID Product
CVE-2025-10366
Key Information:
- Vendor
Miczflor
- Status
- Vendor
- CVE Published:
- 13 September 2025
Badges
What is CVE-2025-10366?
A vulnerability has been identified in MiczFlor RPi-Jukebox-RFID affecting versions up to 2.8.0, specifically in the /htdocs/inc.setWlanIpMail.php file. This flaw arises from improper handling of the Email address argument, which allows for cross-site scripting attacks that can be executed remotely. An attacker can exploit this vulnerability to inject malicious scripts, posing a significant security risk. The vendor has been notified of this issue but has yet to respond.
Affected Version(s)
RPi-Jukebox-RFID 2.0
RPi-Jukebox-RFID 2.1
RPi-Jukebox-RFID 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved