CVE-2025-25476
CVE-2025-25476
Título es
CVE-2025-25476
Vie, 28/02/2025 – 23:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-25476
Descripción en
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.
01/03/2025
01/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://github.com/sysentr0py/CVEs/tree/main/CVE-2025-25476
Enviar en el boletín
Off