Record summary

CVE-2019-25731 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzconsole/___contact, which executes when administrators view messages in the inbox interface.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBZuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site ScriptingExploitDB exploitby Deyaa MuhammadNot analyzed1 file
ExploitDB

PoC details

References

5