Cross Site Scripting Vulnerability in AllStarLink Supermon by AllStarLink
CVE-2025-11278
What is CVE-2025-11278?
A vulnerability has been identified in the AllStarLink Supermon application that affects versions up to 6.2. This security flaw resides within the AllMon2 component, enabling attackers to perform cross site scripting (XSS) attacks remotely. If exploited, this vulnerability can allow unauthorized script execution in the context of a user's web browser, potentially compromising sensitive information or user sessions. The vendor has been contacted regarding this issue, but no response has been received. Additionally, this vulnerability impacts products that are no longer actively maintained.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Supermon 6.0
Supermon 6.1
Supermon 6.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
