Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.
Version 5.20 of MegaBIP fixes this issue.
CVE ID: CVE-2025-3894
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.8
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Vendor: Jan Syski
Product: MegaBIP
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 16.87% (scored less or equal to compared to others)
EPSS Date: 2025-06-18 (when was this score calculated)