PT-2025-45158 · Selfbest · Selfbest

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-63417

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SelfBest version 2023.3
Description A Stored Cross-Site Scripting (XSS) issue exists in the chat functionality of the SelfBest platform. Authenticated attackers can inject arbitrary web scripts or HTML through the chat message input field. This malicious content is stored and executed in the context of other users’ browsers when they view the message, potentially leading to session hijacking or account takeover.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63417

Affected Products

Selfbest