Cross-Site Scripting Vulnerability in PlainInventory by Plainware
CVE-2025-24557
7.1HIGH
What is CVE-2025-24557?
A reflected Cross-Site Scripting (XSS) vulnerability exists in PlainInventory by Plainware, allowing attackers to inject malicious scripts into web pages viewed by users. This flaw can lead to unauthorized actions and data exposure, impacting the integrity and confidentiality of user information. Affected versions include from n/a through 3.1.5, highlighting the urgent need for security updates and user awareness to mitigate potential attacks.
Affected Version(s)
PlainInventory <= 3.1.5