SVX Portal Cross-Site Scripting Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SVX Portal version 2.7A. The issue arises in the 'last_heard_page.php' component, where the 'TG' parameter is vulnerable to reflected XSS attacks. This flaw allows the execution of arbitrary JavaScript in the context of the victim's browser.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing for the execution of malicious scripts in the context of the user's session.

Reproduction

To reproduce this vulnerability, send a request to 'last_heard_page.php' with a crafted 'TG' parameter that includes an image tag (with an invalid image source) using an 'onerror' event. This will trigger the XSS by executing JavaScript in the victim's browser.

Added: Oct 9, 2025, 4:20 PM
Updated: Oct 9, 2025, 7:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
7.7
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.