PT-2025-22126 · Koibox · Koibox
Published
2025-05-20
·
Updated
2025-05-20
·
CVE-2025-40633
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions:
Koibox versions prior to e8cbce2
Description:
A Stored Cross-Site Scripting (XSS) issue has been found, allowing an authenticated attacker to upload an image containing malicious JavaScript code as a profile picture in the "/es/dashboard/clientes/ficha/" endpoint.
Recommendations:
For versions prior to e8cbce2, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the "/es/dashboard/clientes/ficha/" endpoint until a patch is available. Avoid allowing authenticated users to upload images that could contain malicious JavaScript code.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Koibox