Cross Site Scripting Vulnerability in Weaver E-Mobile Mobile Management Platform
CVE-2025-9590
What is CVE-2025-9590?
A vulnerability in the Weaver E-Mobile Mobile Management Platform allows for cross-site scripting via manipulation of the 'gohome' argument. This security flaw can be exploited remotely, enabling attackers to possibly execute malicious scripts. The exploit code is publicly available, raising concerns for users of the affected product versions up to 20250813. Despite prior outreach for a response from the vendor regarding this issue, no communication has been recorded.
Affected Version(s)
E-Mobile Mobile Management Platform 20250813
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved