Multiple Authenticated Stored Cross-Site Scripting
Vulnerability Description
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0424
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Manuel Kiesel (cyllective AG)
- David Miller (cyllective AG)
Affected Vendor
Cordaware
View all reports →