PT-2025-31720 · Partner · Partner Web Application+1

Published

2025-08-02

·

Updated

2025-09-25

·

CVE-2025-6078

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Partner Software's Partner Software application and Partner Web application (affected versions not specified)
Description The application does not completely sanitize input on the 'Notes' page when viewing a job, allowing an authenticated user to add notes containing HTML tags and JavaScript. This can lead to stored cross-site scripting (XSS) where an attacker adds a note containing malicious JavaScript.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-6078

Affected Products

Partner Software Application
Partner Web Application