PT-2025-24003 · Unknown · Soluçõescoop Isoluçõesweb
Syrtain
·
Published
2025-06-06
·
Updated
2025-06-06
·
CVE-2025-5713
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SoluçõesCoop iSoluçõesWEB versions prior to 20250519
Description
A problem was found in some unknown functionality of the file /fluxos-dashboard of the component Flow Handler. The manipulation of the
Descrição da solicitação argument leads to cross site scripting attacks. These attacks can be executed remotely. The exploit has been publicly disclosed and could be used.Recommendations
For versions prior to 20250519, update the affected component to resolve the issue. As a temporary workaround, consider restricting access to the /fluxos-dashboard file of the Flow Handler component to minimize the risk of exploitation. Avoid using the
Descrição da solicitação argument in the affected functionality until the issue is resolved.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Soluçõescoop Isoluçõesweb