A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.Referenceshttps://github.com/shinovon/mpgram-webhttps://mp.nnchan.ru/login.phphttps://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2025-45662