CVE-2025-27102 - CVE House
Back to Database
Status published Medium CVE-2025-27102

Agate vulnerable to HTML injection in user signup - Administrator phishing risk

Vulnerability Description

Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user's first and last name. This HTML is then rendered in the email sent to administrative users. The Agate service account sends this email and appears trustworthy, making this a significant risk for phishing attacks. Administrative users are impacted, as they can be targeted by unauthenticated users. Version 3.3.0 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27102

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

agate
Vulnerable Versions:
< 3.3.0

Timeline

Official Publish: March 17th, 2025
Last Modified: March 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)