CNNVD-202511-2167 Information

CNNVD ID

CNNVD-202511-2167

CVE-2025-63211

  • CNNVD Published: 2025-11-19

Description (Chinese)

Bridgetech VBC Server & Element Manager是挪威Bridgetech公司的一个广播核心软件平台。 Bridgetech VBC Server & Element Manager 6.5.0-9版本至6.5.0-10版本存在安全漏洞,该漏洞源于/vbc/core/userSetupDoc/userSetupDoc端点的addName参数存在存储型跨站脚本,可能导致执行任意代码。

Description (English)

Bridgetech VBC Server & Element Manager is a broadcast core software platform for Bridgetech, Norway. Bridgetech VBC Server & Element Manager 6.5.0-9 to 6.5.0-10 contains a security loophole that originates from the /vbc/core/userSetupDoc/userSetupDoc end-point with a storage-type cross-site script that may result in the implementation of an arbitrary code.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Bridgetech

Published

2025-11-19

Last Modified

2026-02-24

References

https://bridgetech.tv/ https://github.com/shiky8/my–cve-vulnerability-research/tree/main/CVE-2025-63211_bridgetech%20VBC%20Server%20and%20Element%20Manager%20Stored%20%20xss https://access.redhat.com/security/cve/cve-2025-63211

Share on: