PT-2026-7250 · Siemens · Polarion

CVE-2025-40587

·

Publicado

2026-02-10

·

Atualizado

2026-02-12

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Polarion versions prior to 2404.5 Polarion versions prior to 2410.2
Description The application allows arbitrary JavaScript code to be included in document titles. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by creating specially crafted document titles that are later viewed by other users of the application. The attack involves manipulating document titles to inject malicious JavaScript code.
Recommendations Update Polarion to version 2404.5 or later. Update Polarion to version 2410.2 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-02000
CVE-2025-40587

Produtos afetados

Polarion