Stored XSS Vulnerability in MagicInfo9 Server by Samsung
CVE-2026-25200
9.8CRITICAL
What is CVE-2026-25200?
A vulnerable aspect of the MagicInfo9 Server enables authenticated users to upload HTML files without proper validation. This loophole could allow for Stored XSS attacks, potentially leading to account takeovers. The affected versions include those prior to 21.1090.1. Organizations using this software should be aware of the risks and take appropriate measures to secure their systems.
Affected Version(s)
MagicINFO 9 Server 21.1090.1
