In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 18 Feb 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement. | |
Title | Multiple Authenticated Stored Cross-Site Scripting | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2025-02-18T14:44:30.277Z
Reserved: 2025-01-13T14:29:49.603Z
Link: CVE-2025-0424

Updated: 2025-02-18T14:44:26.146Z

Status : Received
Published: 2025-02-18T08:15:10.490
Modified: 2025-02-18T08:15:10.490
Link: CVE-2025-0424

No data.