PT-2026-21109 · Itex · Itex Isape

Published

2026-02-20

·

Updated

2026-02-22

·

CVE-2025-68847

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions itex iSape versions through 0.72
Description The software contains a flaw due to improper neutralization of input during web page generation, leading to a Reflected Cross-Site Scripting (XSS) condition. This allows for the injection of malicious scripts into web pages. The affected component is itex iSape isape.
Recommendations Versions prior to and including 0.72 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68847

Affected Products

Itex Isape