关键信息总结 漏洞概述 标题: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting 严重性: MEDIUM 日期: December 30, 2025 漏洞类型: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 受影响的版本 Impact/Pulse/First Version 2: 1.1/2.15 Impact/Pulse/Eco 1.16 BigVoice4 1.2 BigVoice2 1.30 NeonStream 1.1/2.4.29 VM2 1.11 CVSS评分 CVSS评分: 5.3 CVSS V4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N 参考资料 Zero Science Lab Disclosure (ZSL-2022-5731) Packet Storm Security Exploit Details IBM X-Force Vulnerability Exchange Entry SOUND4 Product Homepage 发现者 LiquidWorm as Gjoko Krstic of Zero Science Lab 描述 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x包含一个未经身份验证的存储型跨站脚本漏洞,该漏洞位于用户名参数中,允许攻击者注入恶意脚本。攻击者可以利用未验证的用户名输入在受害者的浏览器会话中执行任意HTML和JavaScript代码,而无需身份验证。