A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address fields (City, State, Country/Region) is rendered back to the page. Attackers can inject arbitrary JavaScript code, which executes when the affected profile page is viewed. This can lead to session hijacking, cookie theft, or arbitrary script execution in the victim's browser.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 16 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Coohom
Coohom coohom
CPEs cpe:2.3:a:coohom:coohom:2025-10-28:*:*:*:*:*:*:*
Vendors & Products Coohom
Coohom coohom

Thu, 11 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 19:00:00 +0000

Type Values Removed Values Added
Description A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address fields (City, State, Country/Region) is rendered back to the page. Attackers can inject arbitrary JavaScript code, which executes when the affected profile page is viewed. This can lead to session hijacking, cookie theft, or arbitrary script execution in the victim's browser.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-11T19:37:29.852Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65300

cve-icon Vulnrichment

Updated: 2025-12-11T19:15:05.979Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T19:15:49.410

Modified: 2025-12-16T19:57:18.740

Link: CVE-2025-65300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses