A Stored Cross-Site Scripting (XSS) vulnerability has been found in
Koibox for versions prior to e8cbce2. This vulnerability allows an
authenticated attacker to upload an image containing malicious
JavaScript code as profile picture in the
'/es/dashboard/clientes/ficha/' endpoint
Metrics
Affected Vendors & Products
References
History
Tue, 20 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 20 May 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Stored Cross-Site Scripting (XSS) vulnerability has been found in Koibox for versions prior to e8cbce2. This vulnerability allows an authenticated attacker to upload an image containing malicious JavaScript code as profile picture in the '/es/dashboard/clientes/ficha/' endpoint | |
Title | Stored Cross-Site Scripting (XSS) in Koibox | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-05-20T10:17:00.222Z
Updated: 2025-05-20T13:19:41.492Z
Reserved: 2025-04-16T08:38:09.209Z
Link: CVE-2025-40633

Updated: 2025-05-20T13:19:18.859Z

Status : Awaiting Analysis
Published: 2025-05-20T11:15:48.630
Modified: 2025-05-21T20:25:16.407
Link: CVE-2025-40633

No data.