In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application. | |
| Title | Multiple Unauthenticated Stored Cross-Site Scripting | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published: 2025-02-18T07:57:17.412Z
Updated: 2025-02-18T14:49:45.731Z
Reserved: 2025-01-13T14:29:48.619Z
Link: CVE-2025-0423
Updated: 2025-02-18T14:49:41.177Z
Status : Received
Published: 2025-02-18T08:15:10.360
Modified: 2025-02-18T08:15:10.360
Link: CVE-2025-0423
No data.