Cross-Site Scripting Vulnerability in Schiocco Support Board
CVE-2025-54027
7.1HIGH
What is CVE-2025-54027?
The Schiocco Support Board is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability that occurs due to improper neutralization of input during web page generation. Attackers can exploit this weakness to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and data exposure. This vulnerability affects all versions from n/a through 3.8.0, highlighting the need for prompt remediation to ensure the security of applications utilizing this product.
Affected Version(s)
Support Board <= 3.8.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)