CVE 7.1 HIGH

Stored Cross-Site Scripting via XML Injection_CVE-2025-66258

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N

Description

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml.
User-controlled filenames are directly concatenated into `patchlist.xml` without encoding, allowing injection of malicious JavaScript payloads via crafted filenames (e.g., `<img src=x onerror=alert()>.bin`). The XSS executes when ajax.js processes and renders the XML file.

Basic Information

ID CVE-2025-66258
Source Gridware
Published Nov 26, 2025 at 00:45

Affected Product

Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30
Affected Versions DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 30
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 50
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 100
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 300
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 1000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 2000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 6000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 7000

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.