CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. Its EPSS score suggests a 18.1% probability of exploitation in the next 30 days.
CVE
CVE-2025-36558
Severity
MEDIUM
CVSS
6.1
EPSS
18.13%
Original NVD Description
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.