CVE-2025-0878: XSS in Akinsoft's LimonDesk
Published Sep 3, 2025
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS).
This issue affects LimonDesk: from s1.02.14 before v1.02.17.
Affected Software
1 affected component
Akinsoft LimonDesk>=s1.02.14<v1.02.17
Event History
Sep 3, 2025
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0878?
CVE-2025-0878 is considered a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2025-0878?
To fix CVE-2025-0878, upgrade Akinsoft LimonDesk to version 1.02.17 or later.
3
What are the consequences of CVE-2025-0878?
The consequences of CVE-2025-0878 include unauthorized access to user sessions and the potential for data theft through Cross-Site Scripting.
4
Which versions of Akinsoft LimonDesk are affected by CVE-2025-0878?
Akinsoft LimonDesk versions from 1.02.14 before 1.02.17 are affected by CVE-2025-0878.
5
Is CVE-2025-0878 easy to exploit?
Yes, CVE-2025-0878 can be easily exploited by attackers familiar with Cross-Site Scripting techniques.