First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound SpatialMatch IDX allows Reflected XSS. This issue affects SpatialMatch IDX: from n/a through 3.0.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound SpatialMatch IDX | <=3.0.9 | |
Home Junction SpatialMatch IDX | <=3.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28921 has a medium severity level due to its potential to allow reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-28921, upgrade to SpatialMatch IDX version 3.1 or later, which addresses the XSS vulnerability.
CVE-2025-28921 affects all versions of SpatialMatch IDX up to and including version 3.0.9.
The impact of CVE-2025-28921 allows an attacker to execute arbitrary scripts in the context of another user’s session.
As a temporary measure, input validation and sanitization can be implemented to mitigate XSS risks from CVE-2025-28921 until an update is applied.