Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 12 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kostasmitroglou:thesystem:1.0.0:*:*:*:*:*:*:* |
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kostasmitroglou
Kostasmitroglou thesystem |
|
| Vendors & Products |
Kostasmitroglou
Kostasmitroglou thesystem |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple server data input fields. Attackers can submit crafted script payloads in operating_system, system_owner, system_username, system_password, system_description, and server_name parameters to execute arbitrary JavaScript in victim browsers. | |
| Title | thesystem Persistent XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T16:03:20.025Z
Reserved: 2026-02-11T14:30:04.408Z
Link: CVE-2019-25311
Updated: 2026-02-11T16:03:16.950Z
Status : Analyzed
Published: 2026-02-11T15:16:09.900
Modified: 2026-03-12T18:52:42.650
Link: CVE-2019-25311
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:37:56Z