Security Advisory
CVE-2025-48168
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky allows Reflected XSS.This issue affects Apollo - Sticky Full Width HTML5 Audio Player: from n/a through <= 3.4.