CVE-2019-25233

MEDIUM

AVE DOMINAplus 1.10.x - Cross-Site Request Forgery and Cross-Site Scripting via login.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25233. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates CSRF and XSS vulnerabilities in AVE DOMINAplus 1.10.x. It includes proof-of-concept HTML forms and HTTP requests to exploit these vulnerabilities, such as enabling/disabling alarms and injecting malicious scripts.

Description

AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/47821

This exploit demonstrates CSRF and XSS vulnerabilities in AVE DOMINAplus 1.10.x. It includes proof-of-concept HTML forms and HTTP requests to exploit these vulnerabilities, such as enabling/disabling alarms and injecting malicious scripts.

Classification
Working Poc 90%
Attack Type
Xss | Csrf
Complexity
Trivial
Reliability
Reliable
Target: AVE DOMINAplus <=1.10.x
Auth required
Prerequisites: Victim must be authenticated · Victim must visit a malicious site
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Various Sources product
https://www.ave.it
Various Sources product
https://www.domoticaplus.it
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5547.php
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47821

Scores

CVSS v3 5.3
EPSS 0.0017
EPSS Percentile 7.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352 CWE-79
Status published
Products (1)
AVE S.p.A./DOMINAplus Web Server Code 53AB-WBS - 1.10.62
Published Dec 24, 2025
Tracked Since Feb 18, 2026