CVE-2025-57462

Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:machsol:machpanel:8.0.32:*:*:*:*:*:*:*

History

31 Dec 2025, 20:13

Type Values Removed Values Added
First Time Machsol
Machsol machpanel
CPE cpe:2.3:a:machsol:machpanel:8.0.32:*:*:*:*:*:*:*
References () https://github.com/aljoharasubaie/CVE-2025-57462/blob/main/README.md - () https://github.com/aljoharasubaie/CVE-2025-57462/blob/main/README.md - Third Party Advisory
References () https://www.machsol.com/ - () https://www.machsol.com/ - Product

30 Dec 2025, 15:15

Type Values Removed Values Added
Summary (en) Reflected Cross site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file. (en) Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.

29 Dec 2025, 17:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

29 Dec 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-29 15:16

Updated : 2025-12-31 20:13


NVD link : CVE-2025-57462

Mitre link : CVE-2025-57462

CVE.ORG link : CVE-2025-57462


JSON object : View

Products Affected

machsol

  • machpanel
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')