A Stored Cross-Site Scripting (XSS) vulnerability has been found in
Koibox for versions prior to e8cbce2. This vulnerability allows an
authenticated attacker to upload an image containing malicious
JavaScript code as profile picture in the
'/es/dashboard/clientes/ficha/' endpoint
CVSS
No CVSS.
References
Configurations
No configuration.
History
20 May 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-20 11:15
Updated : 2025-05-21 20:25
NVD link : CVE-2025-40633
Mitre link : CVE-2025-40633
CVE.ORG link : CVE-2025-40633
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')