In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement. | |
| Title | Multiple Authenticated Stored Cross-Site Scripting | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published: 2025-02-18T07:57:25.806Z
Updated: 2025-02-18T14:44:30.277Z
Reserved: 2025-01-13T14:29:49.603Z
Link: CVE-2025-0424
Updated: 2025-02-18T14:44:26.146Z
Status : Received
Published: 2025-02-18T08:15:10.490
Modified: 2025-02-18T08:15:10.490
Link: CVE-2025-0424
No data.