Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4819 | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 18 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement. | |
| Title | Multiple Authenticated Stored Cross-Site Scripting | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2025-02-18T14:44:30.277Z
Reserved: 2025-01-13T14:29:49.603Z
Link: CVE-2025-0424
Updated: 2025-02-18T14:44:26.146Z
Status : Received
Published: 2025-02-18T08:15:10.490
Modified: 2025-02-18T08:15:10.490
Link: CVE-2025-0424
No data.
OpenCVE Enrichment
No data.
EUVD