Record summary

CVE-2019-25356 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a cross-site scripting vulnerability in the admin configuration page. Attackers can inject malicious scripts via crafted POST requests with malformed 'admin' and 'person' parameters, allowing execution of arbitrary JavaScript in the context of an authenticated user's browser session.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListVersion range not suppliedaffected

Proofs of concept

1

Catalogued exploits

ExploitDBBematech Printer MP-4200 - Denial of ServiceExploitDB exploitby Jonatas FilNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5