Stored XSS in Kron Technologies' Kron PAM
Vulnerability Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS. This issue affects Kron PAM: before 3.7.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5254
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Taha Yildirim
- Türk Telekom
References
More from Kron Technologies
View All →Affected Vendor
Kron Technologies
View all reports →