CVE-2025-51962

Publication date

2025-12-15 00:00:00

Family

mitre

State

PUBLISHED

Description

A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML via the text parameter of add_project_comment function.