go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Simopro Technology|WinMatrix3 Web package - Reflected Cross-Site Scripting

TVN ID TVN-202507011
CVE ID CVE-2025-7920
CVSS 6.1 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products WinMatrix Web version 1.2.39.5 and earlier
Description WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Solution Update AP to version 3.8.52.5 (Web 1.2.39.5) and install the hotfix, or update AP to version 3.9.1 (Web 1.3.1) or later
Credit XY(DEVCORE)
Public Date 2025-07-21
Top