CVE-2025-0423 - CVE House
Back to Database
Status published Medium CVE-2025-0423

Multiple Unauthenticated Stored Cross-Site Scripting

Vulnerability Description

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0423

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Manuel Kiesel (cyllective AG)
  • David Miller (cyllective AG)

Affected Vendor

Affected Software

bestinformed Web
Vulnerable Versions:
0, 6.2.2.5

Timeline

Official Publish: February 18th, 2025
Last Modified: February 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)