Junglewise Threat Intelligence

CVE-2025-0643: Narkom Pyxis Signage Stored XSS

CVE-2025-0643 · Severity: high · CVSS 7.2 · Published 2025-11-20

Executive brief

A security vulnerability exists in Pyxis Signage, a digital signage platform used to manage and display content on remote screens. An attacker with administrative access can inject malicious scripts into the system that remain stored on the server. When other users or administrators view the affected management pages, these scripts could execute, potentially leading to unauthorized data access or full control over the signage displays.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Narkom Pyxis Signage through version 31012025. The flaw is caused by improper neutralization of user-provided input during web page generation (CWE-79). An attacker with high privileges (PR:H) can inject malicious JavaScript into the application's database. This script is later executed in the context of any user who views the compromised content. While the attack requires high privileges, the impact is significant, potentially allowing for session hijacking or unauthorized administrative actions.

Affected products

  • Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage through 31012025

Timeline

  • 2025-11-20: disclosed
  • 2025-11-20: advisory

References

Related threats