A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover
This issue affects MagicINFO 9 Server: less than 21.1090.1.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://security.samsungtv.com/securityUpdates |
|
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samsung Electronics
Samsung Electronics magicinfo 9 Server |
|
| Vendors & Products |
Samsung Electronics
Samsung Electronics magicinfo 9 Server |
Mon, 02 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1. | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: samsung.tv_appliance
Published: 2026-02-02T04:49:13.086Z
Updated: 2026-02-03T04:55:45.720Z
Reserved: 2026-01-30T06:07:11.090Z
Link: CVE-2026-25200
Updated: 2026-02-02T17:54:35.496Z
Status : Awaiting Analysis
Published: 2026-02-02T05:16:05.770
Modified: 2026-02-03T16:44:36.630
Link: CVE-2026-25200
No data.
ReportizFlow