In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.
CVSS
No CVSS.
References
Configurations
No configuration.
History
18 Feb 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-18 08:15
Updated : 2025-02-18 08:15
NVD link : CVE-2025-0423
Mitre link : CVE-2025-0423
CVE.ORG link : CVE-2025-0423
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation