CVE-2025-25476: XSS
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25476?
CVE-2025-25476 has a severity rating that indicates a significant risk due to its potential for executing arbitrary JavaScript code.
How do I fix CVE-2025-25476?
To fix CVE-2025-25476, update SysPass to the latest version that addresses this stored cross-site scripting vulnerability.
Who is affected by CVE-2025-25476?
Users of SysPass version 3.2.0 and above are affected by CVE-2025-25476 due to the stored XSS vulnerability.
What type of vulnerability is CVE-2025-25476?
CVE-2025-25476 is a stored cross-site scripting (XSS) vulnerability that allows execution of arbitrary code.
What can a malicious user do with CVE-2025-25476?
A malicious user with elevated privileges can exploit CVE-2025-25476 to execute arbitrary JavaScript code impacting other users.