Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/TemplatePreview.aspx endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. User-supplied input is stored and later rendered in HTML pages without proper output encoding or sanitization. This allows attackers to persistently inject arbitrary JavaScript that executes in the context of other users' sessions
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 08 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/TemplatePreview.aspx endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. User-supplied input is stored and later rendered in HTML pages without proper output encoding or sanitization. This allows attackers to persistently inject arbitrary JavaScript that executes in the context of other users' sessions | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-08T00:00:00.000Z
Updated: 2026-01-08T19:43:11.814Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61550
Updated: 2026-01-08T19:30:59.656Z
Status : Awaiting Analysis
Published: 2026-01-08T17:15:48.940
Modified: 2026-01-08T20:15:44.357
Link: CVE-2025-61550
No data.