Stored XSS Vulnerability in MagicInfo9 Server by Samsung
CVE-2026-25200
9.8CRITICAL
What is CVE-2026-25200?
A vulnerable aspect of the MagicInfo9 Server enables authenticated users to upload HTML files without proper validation. This loophole could allow for Stored XSS attacks, potentially leading to account takeovers. The affected versions include those prior to 21.1090.1. Organizations using this software should be aware of the risks and take appropriate measures to secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MagicINFO 9 Server 21.1090.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
