Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated attacker to upload a malicious SVG image into the user's personal space in /CronosWeb/Modules/Persons/PersonalDocuments/PersonalDocuments. There is no reported fix at this time.
History

Tue, 27 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 May 2025 13:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated attacker to upload a malicious SVG image into the user's personal space in /CronosWeb/Modules/Persons/PersonalDocuments/PersonalDocuments. There is no reported fix at this time.
Title Stored Cross-Site Scripting (XSS) in i2A-Cronos by i2A
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-05-26T12:55:30.974Z

Updated: 2025-05-27T14:12:00.795Z

Reserved: 2025-04-16T08:38:13.919Z

Link: CVE-2025-40663

cve-icon Vulnrichment

Updated: 2025-05-27T14:11:49.686Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-26T13:15:20.000

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-40663

cve-icon Redhat

No data.