CVE-2025-3894

Publication date

2025-05-23 10:20:03

Family

CERT-PL

State

PUBLISHED

Description

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.