Key Information Summary Vulnerability Name: - STVS ProVision 5.9.10 Authenticated Reflected Cross-Site Scripting via Files Parameter Severity: - Medium Date: - December 31, 2025 Affected Versions: - STVS ProVision 5.9.10, 5.9.9, 5.9.7, 5.9.1, 5.9.0, 5.8.6, 5.7, 5.6, 5.5 Vulnerability Type & ID: - CVE: CVE-2021-47725 - CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVSS Rating: - 6.1/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N References: - Zero Science Lab Disclosure (ZSL-2021-5624) - Packet Storm Security Exploit Entry - CXSecurity Vulnerability Listing - IBM X-Force Vulnerability Exchange - Vendor Homepage Discoverer: - LiquidWorm as Gjoko Krstic of Zero Science Lab Vulnerability Description: - A cross-site scripting (XSS) vulnerability exists in the 'files' POST parameter of STVS ProVision 5.9.10, allowing authenticated attackers to inject arbitrary HTML code. Attackers can exploit this unvalidated input to execute malicious scripts within the context of the affected site during a user’s browser session.