CVE-2025-36558
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 18.85%
- CWE
- CWE-97
- Published
- 2025-05-01
- Last modified
- 2026-03-13
Affected products
- KUNBUS GmbH Revolution Pi PiCtory
Weakness type
Related vulnerabilities
- CVE-2023-53934 — Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service
- CVE-2025-35996 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-21103 — Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7...
- CVE-2024-56363 — APTRS has SSTI vulnerability