Cross-site Scripting Vulnerability in Digital Zoom Studio Demo User from Vendor Digital Zoom
CVE-2025-23581
6.5MEDIUM
Summary
A Stored XSS vulnerability exists in the Digital Zoom Studio Demo User plugin which allows attackers to inject malicious scripts through improper input handling during web page generation. This can lead to unauthorized access to user data and facilitate further attacks within the web application. The issue affects versions of the Demo User DZS plugin from n/a through 1.1.0, underscoring the importance of timely updates and rigorous input validation to safeguard web applications.
Affected Version(s)
Demo User DZS <= 1.1.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SOPROBRO (Patchstack Alliance)