CVE-2025-0546
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-17

Last updated on: 2025-09-17

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges.Β This issue affects MevzuatTR: before 12.02.2025.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-17
Last Modified
2025-09-17
Generated
2026-05-07
AI Q&A
2025-09-17
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
mevzuattr mevzuattrtr *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1021 The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS), combined with Improper Restriction of Rendered UI Layers or Frames in the Mevzuattr Software MevzuatTR. It allows attackers with high privileges to perform phishing, iFrame overlay, clickjacking, and forceful browsing attacks by exploiting how the software handles input and UI rendering.


How can this vulnerability impact me? :

If exploited, this vulnerability can lead to phishing attacks, where users may be tricked into revealing sensitive information. It can also enable iFrame overlay and clickjacking attacks, potentially causing users to unknowingly perform actions or disclose data. Additionally, forceful browsing may allow unauthorized access to restricted areas. Overall, it can compromise confidentiality, integrity, and availability of the system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart