Junglewise Threat Intelligence

CVE-2026-27504: sa2blv SVXportal reflected XSS in radiomobile_front.php

CVE-2026-27504 · Severity: medium · CVSS 6.1 · Published 2026-02-20

Technologies: Radioinorr Svxportal. Vendors: Radioinorr.

Executive brief

SVXportal, a web portal for managing radio station nodes, contains a security flaw that allows attackers to execute malicious scripts in an administrator's browser. By tricking a logged-in administrator into clicking a specially crafted link, an attacker could hijack their session or perform unauthorized administrative actions. This could lead to a full compromise of the portal's management interface and its connected radio infrastructure.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in SVXportal version 2.5 and earlier within the 'radiomobile_front.php' component. The root cause is the improper neutralization of the 'stationid' query parameter before it is embedded into a hidden input field's value attribute. An unauthenticated remote attacker can exploit this by inducing an authenticated administrator to visit a crafted URL. Successful exploitation allows for the execution of arbitrary JavaScript in the victim's browser session, potentially leading to session token theft or unauthorized administrative configuration changes. As of the advisory date, no official patch has been confirmed, though users are advised to sanitize input or restrict access to the administrative interface.

Affected products

  • sa2blv SVXportal <= 2.5

Timeline

  • 2026-02-20: disclosed
  • 2026-02-20: advisory

References

Related threats