VYPR
Unrated severityNVD Advisory· Published Nov 26, 2025· Updated Nov 26, 2025

Stored Cross-Site Scripting via XML Injection

CVE-2025-66258

Description

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml. User-controlled filenames are directly concatenated into patchlist.xml without encoding, allowing injection of malicious JavaScript payloads via crafted filenames (e.g., .bin). The XSS executes when ajax.js processes and renders the XML file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.

CVE-2025-66258 · VYPR