Home

Description

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious JavaScript payload into the ?m= query parameter, an attacker can execute arbitrary code in the victim's browser, potentially stealing sensitive information, hijacking sessions, or performing unauthorized actions.

PUBLISHED Reserved 2025-10-27 | Published 2025-11-18 | Updated 2025-11-19 | Assigner mitre

References

www.dbbroadcast.com/

github.com/.../main/CVE-2025-63229_Mozart_FM_Transmitter_xss

cve.org (CVE-2025-63229)

nvd.nist.gov (CVE-2025-63229)

Download JSON