Latest: CVE-2019-25277 - FaceSentry Access Control System 6.4.8 Reflected Cross-Site Scripting via plugin...

Latest: CVE-2019-25277 - FaceSentry Access Control System 6.4.8 Reflected Cross-Site Scripting via plugin...

CVE ID : CVE-2019-25277 Published : Jan. 8, 2026, 12:15 a.m. | 15 minutes ago Description : FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginInstall.php that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated input to execute arbitrary JavaScript in victim browsers, potentially stealing authentication credentials and conducting phishing attacks. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 8, 2026
Affected Product: php

Source: Telegram CVE Monitor