CNNVD-202511-2167 Information
CNNVD ID
CNNVD-202511-2167
Related CVE
- CNNVD Published: 2025-11-19
Description (Chinese)
Bridgetech VBC Server & Element Manager是挪威Bridgetech公司的一个广播核心软件平台。 Bridgetech VBC Server & Element Manager 6.5.0-9版本至6.5.0-10版本存在安全漏洞,该漏洞源于/vbc/core/userSetupDoc/userSetupDoc端点的addName参数存在存储型跨站脚本,可能导致执行任意代码。
Description (English)
Bridgetech VBC Server & Element Manager is a broadcast core software platform for Bridgetech, Norway. Bridgetech VBC Server & Element Manager 6.5.0-9 to 6.5.0-10 contains a security loophole that originates from the /vbc/core/userSetupDoc/userSetupDoc end-point with a storage-type cross-site script that may result in the implementation of an arbitrary code.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Bridgetech
Published
2025-11-19
Last Modified
2026-02-24
References
https://bridgetech.tv/ https://github.com/shiky8/my–cve-vulnerability-research/tree/main/CVE-2025-63211_bridgetech%20VBC%20Server%20and%20Element%20Manager%20Stored%20%20xss https://access.redhat.com/security/cve/cve-2025-63211
Share on: