CVE-2026-27504

MEDIUM

SVXportal < 2.5 - Authenticated Reflected Cross-Site Scripting via stationid Parameter

Title source: llm
STIX 2.1

Description

SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the stationid query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value into a hidden input value field, allowing attacker-supplied script injection and execution in the administrator's browser. This can be used to compromise admin sessions or perform unauthorized actions via the administrator's authenticated context.

Scores

CVSS v3 6.1
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
radioinorr/svxportal < 2.5
sa2blv/SVXportal < 2.5
Published Feb 20, 2026
Tracked Since Feb 21, 2026