Security Advisory

CVE-2025-41024

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-20 11:35:31
Last updated 2026-01-20 16:46:49
Assigner INCIBE
CVSS score 5.1
State PUBLISHED

Description

Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user input by sending a POST request. The relationship between parameters and assigned identifiers is as follows:  'companyaddress', 'companyemail', 'companyname', 'country', 'mobilenumber' y 'regno' parameters in '/farm/farmprofile.php'.