๐Ÿ” CVE Alert

CVE-2019-25731

MEDIUM 6.1

Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact

CVSS Score
6.1
EPSS Score
0.1%
EPSS Percentile
24th

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzconsole/___contact, which executes when administrators view messages in the inbox interface.

CWE CWE-79
Vendor zuz
Product zuz music
Published Jun 4, 2026
Last Updated Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for zuz zuz music

Be the first to know when new medium vulnerabilities affecting zuz zuz music are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Zuz / Zuz Music
2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/46420 zuz.host: https://zuz.host/ codecanyon.net: https://codecanyon.net/item/zuz-music-advance-music-platform-system/21633476 vulncheck.com: https://www.vulncheck.com/advisories/zuz-music-persistent-cross-site-scripting-via-zuzconsole-contact

Credits

Deyaa Muhammad