CVE-2025-60948
EUVD-2025-20895223.03.2026, 22:16
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| csprousers | csweb | 8.0.1 |
𝑥
= Vulnerable software versions