Cross-Site Scripting (XSS) in CoverManager
Vulnerability Description
Stored Cross-Site Scripting (XSS) vulnerability in the CoverManager booking software. This allows an attacker to inject malicious scripts into the application, which are permanently stored on the server. The malicious scripts are executed in the browser of any user visiting the affected page without the user having to take any further action. This can allow the attacker to steal sensitive information, such as session cookies, login credentials, and perform actions on behalf of the affected user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40652
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Javier Paradelo Rodriguez
Affected Vendor
CoverManager
View all reports →