Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 08 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-08T00:00:00.000Z
Updated: 2026-01-08T19:43:41.290Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61549
Updated: 2026-01-08T19:31:11.261Z
Status : Awaiting Analysis
Published: 2026-01-08T17:15:48.830
Modified: 2026-01-08T20:15:44.210
Link: CVE-2025-61549
No data.