{"api_version":"1","generated_at":"2026-06-06T17:55:11+00:00","cve":"CVE-2025-0546","urls":{"html":"https://cve.report/CVE-2025-0546","api":"https://cve.report/api/cve/CVE-2025-0546.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-0546","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-0546"},"summary":{"title":"XSS in Mevzuattr Software's MevzuatTR","description":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges. \n\nThis issue affects MevzuatTR: before 12.02.2025.","state":"PUBLISHED","assigner":"TR-CERT","published_at":"2025-09-17 12:15:37","updated_at":"2026-06-06 08:16:46"},"problem_types":["CWE-79","CWE-1021","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","CWE-1021 CWE-1021 Improper Restriction of Rendered UI Layers or Frames"],"metrics":[{"version":"3.1","source":"iletisim@usom.gov.tr","type":"Secondary","score":"4.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0269","name":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0269","refsource":"iletisim@usom.gov.tr","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.usom.gov.tr/bildirim/tr-25-0269","name":"https://www.usom.gov.tr/bildirim/tr-25-0269","refsource":"iletisim@usom.gov.tr","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-0546","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0546","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Mevzuattr Software","product":"MevzuatTR","version":"affected 12.02.2025 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Berat Arslan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-0546","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-09-17T13:07:57.394790Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-09-17T13:08:06.681Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"MevzuatTR","vendor":"Mevzuattr Software","versions":[{"lessThan":"12.02.2025","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Berat Arslan"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges.&nbsp;<p>This issue affects MevzuatTR: before 12.02.2025.</p>"}],"value":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges. \n\nThis issue affects MevzuatTR: before 12.02.2025."}],"impacts":[{"capecId":"CAPEC-98","descriptions":[{"lang":"en","value":"CAPEC-98 Phishing"}]},{"capecId":"CAPEC-222","descriptions":[{"lang":"en","value":"CAPEC-222 iFrame Overlay"}]},{"capecId":"CAPEC-103","descriptions":[{"lang":"en","value":"CAPEC-103 Clickjacking"}]},{"capecId":"CAPEC-87","descriptions":[{"lang":"en","value":"CAPEC-87 Forceful Browsing"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-1021","description":"CWE-1021 Improper Restriction of Rendered UI Layers or Frames","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-06T07:34:08.550Z","orgId":"ca940d4e-fea4-4aa2-9a58-591a58b1ce21","shortName":"TR-CERT"},"references":[{"tags":["government-resource","broken-link"],"url":"https://www.usom.gov.tr/bildirim/tr-25-0269"},{"tags":["government-resource"],"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0269"}],"source":{"advisory":"TR-25-0269","defect":["TR-25-0269"],"discovery":"UNKNOWN"},"title":"XSS in Mevzuattr Software's MevzuatTR","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"ca940d4e-fea4-4aa2-9a58-591a58b1ce21","assignerShortName":"TR-CERT","cveId":"CVE-2025-0546","datePublished":"2025-09-17T11:42:42.358Z","dateReserved":"2025-01-17T13:47:20.099Z","dateUpdated":"2026-06-06T07:34:08.550Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-09-17 12:15:37","lastModifiedDate":"2026-06-06 08:16:46","problem_types":["CWE-79","CWE-1021","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","CWE-1021 CWE-1021 Improper Restriction of Rendered UI Layers or Frames"],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":3.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"546","Ordinal":"1","Title":"XSS in Mevzuattr Software's MevzuatTR","CVE":"CVE-2025-0546","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"546","Ordinal":"1","NoteData":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges. \n\nThis issue affects MevzuatTR: before 12.02.2025.","Type":"Description","Title":"XSS in Mevzuattr Software's MevzuatTR"}]}}}