---
id: CVE-2025-0546
title: >-
  Improper Neutralization of Input During Web Page Generation (XSS or
  'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames
  vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay,
  Clickjacking…
summary: >-
  Improper Neutralization of Input During Web Page Generation (XSS or
  'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames
  vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay,
  Clickjacking…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-79
  - CWE-1021
published: '2025-09-17'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-0546'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0269'
    label: iletisim@usom.gov.tr
  - url: 'https://www.usom.gov.tr/bildirim/tr-25-0269'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00252
epssPercentile: 0.14866
ingestedAt: '2026-09-26T00:22:39.926Z'
---

## Overview

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges. 

This issue affects MevzuatTR: before 12.02.2025.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
