Description
A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/cardEdit.php. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
In MiczFlor RPi-Jukebox-RFID bis 2.8.0 ist eine Schwachstelle entdeckt worden. Betroffen hiervon ist ein unbekannter Ablauf der Datei /htdocs/cardEdit.php. Die Manipulation führt zu cross site scripting. Der Angriff kann remote ausgeführt werden. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8.0
Timeline
| 2025-09-12: | Advisory disclosed |
| 2025-09-12: | VulDB entry created |
| 2025-09-12: | VulDB entry last update |
Credits
XU17 (VulDB User)
References
vuldb.com/?id.323775 (VDB-323775 | MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting)
vuldb.com/?ctiid.323775 (VDB-323775 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.643518 (Submit #643518 | MiczFlor RPi-Jukebox-RFID 2.8.0 XSS)
github.com/YZS17/CVE/blob/main/RPi-Jukebox-RFID/xss2.md
github.com/YZS17/CVE/blob/main/RPi-Jukebox-RFID/xss2.md