Multiple Unauthenticated Stored Cross-Site Scripting
Vulnerability Description
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0423
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Manuel Kiesel (cyllective AG)
- David Miller (cyllective AG)
Affected Vendor
Cordaware
View all reports →