PT-2025-5626 · Monicahq+1 · Monicahq+1
Cipherboy
·
Published
2025-01-20
·
Updated
2025-09-12
·
CVE-2025-54997
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MonicaHQ version 4.1.1
Description:
The issue allows attackers to exploit authenticated client-side injection in journal entry edits, with a medium severity level. A patch is pending, and users should monitor updates closely.
Recommendations:
For version 4.1.1, update to a newer version once the pending patch is released to resolve the issue. As a temporary workaround, consider restricting access to journal entry edits until the patch is available.
Exploit
Fix
LPE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Monicahq
Red Os