๐Ÿ” CVE Alert

CVE-2021-47725

MEDIUM 5.4

STVS ProVision 5.9.10 Authenticated Reflected Cross-Site Scripting via Files Parameter

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site.

CWE CWE-79
Vendor stvs sa
Product stvs provision
Published Dec 31, 2025
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for stvs sa stvs provision

Be the first to know when new medium vulnerabilities affecting stvs sa stvs provision are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

STVS SA / STVS ProVision
5.9.10 5.9.9 5.9.7 5.9.1 5.9.0 5.8.6 5.7 5.6 5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zeroscience.mk: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5624.php packetstormsecurity.com: https://packetstormsecurity.com/files/161158/STVS-ProVision-5.9.10-Cross-Site-Scripting.html cxsecurity.com: https://cxsecurity.com/issue/WLB-2021010188 exchange.xforce.ibmcloud.com: https://exchange.xforce.ibmcloud.com/vulnerabilities/195723 stvs.com: https://stvs.com/ vulncheck.com: https://www.vulncheck.com/advisories/stvs-provision-authenticated-reflected-cross-site-scripting-via-files-parameter

Credits

LiquidWorm as Gjoko Krstic of Zero Science Lab