CVE-2019-25294

html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in victim browsers when the page is loaded.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lolypop55:html5_snmp:-:*:*:*:*:*:*:*

History

17 Jun 2026, 02:31

Type Values Removed Values Added
Summary
  • (es) html5_snmp 1.11 contiene una persistente vulnerabilidad de cross-site scripting que permite a los atacantes inyectar scripts maliciosos a través del parámetro 'Remark' en add_router_operation.PHP. Los atacantes pueden elaborar una solicitud POST con una carga útil de script en el campo Remark para ejecutar JavaScript arbitrario en los navegadores de las víctimas cuando se carga la página.

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 6.1

24 Feb 2026, 21:15

Type Values Removed Values Added
First Time Lolypop55 html5 Snmp
Lolypop55
CPE cpe:2.3:a:lolypop55:html5_snmp:-:*:*:*:*:*:*:*
References () https://github.com/lolypop55/html5_snmp - () https://github.com/lolypop55/html5_snmp - Product
References () https://www.exploit-db.com/exploits/47587 - () https://www.exploit-db.com/exploits/47587 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/htmlsnmp-remark-persistent-cross-site-scripting - () https://www.vulncheck.com/advisories/htmlsnmp-remark-persistent-cross-site-scripting - Broken Link

06 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 17:16

Updated : 2026-06-17 02:31


NVD link : CVE-2019-25294

Mitre link : CVE-2019-25294

CVE.ORG link : CVE-2019-25294


JSON object : View

Products Affected

lolypop55

  • html5_snmp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')