Description
Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required. Version 5.20 of MegaBIP fixes this issue.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version
Credits
Kamil Szczurowski
Robert Kruczek
References
cert.pl/en/posts/2025/05/CVE-2025-3893
megabip.pl/index.php?id=24,145
www.gov.pl/...twa-dotyczaca-biuletynow-informacji-publicznej