PT-2025-53901 · Tribulant · Newsletters-Lite

Dj

+1

·

Published

2025-12-30

·

Updated

2025-12-30

·

CVE-2025-69020

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tribulant Software Newsletters newsletters-lite versions through 4.12
Description The software contains a flaw due to improper neutralization of input during web page generation, leading to a Cross-site Scripting issue. This allows for Stored XSS attacks. The vulnerability exists in the way the application handles user-supplied data when generating web pages.
Recommendations Versions prior to 4.12 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-69020

Affected Products

Newsletters-Lite