PT-2025-52052 · Unknown · Venusweb Logtik

Tran Nguyen Bao Khanh

·

Published

2025-12-18

·

Updated

2025-12-19

·

CVE-2025-57897

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions venusweb Logtik versions prior to 2.3
Description The software contains a flaw related to improper input handling during web page generation, which allows for Reflected Cross-site Scripting (XSS). This means that malicious code can be injected into web pages viewed by users. The vulnerable component allows attackers to inject scripts into the affected application. The vulnerable parameter is not specified.
Recommendations Update venusweb Logtik to a version newer than 2.3.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57897

Affected Products

Venusweb Logtik