First published: Wed Mar 19 2025(Updated: )
Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intrexx Portal Server | <=12.0.2 | |
Intrexx Portal Server | <=11.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30092 is assessed as a moderate severity vulnerability due to its potential to enable cross-site scripting (XSS) attacks.
To fix CVE-2025-30092, update the Intrexx Portal Server to version 12.0.3 or later for the 12.x branch and 11.9.3 or later for the 11.x branch.
CVE-2025-30092 can facilitate cross-site scripting (XSS) attacks that may allow an attacker to inject malicious scripts.
CVE-2025-30092 affects Intrexx Portal Server versions 12.x up to and including 12.0.2 and 11.x up to and including 11.9.2.
Yes, CVE-2025-30092 can impact user session security by enabling attackers to hijack sessions through XSS vulnerabilities.