CVE-2025-40647: Stored Cross-Site Scripting (XSS) vulnerability in Issabel products
Published Oct 1, 2025
·Updated
Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper validation of user input, through the 'email' parameter in '/index.php?menu=addressbook'.
Affected Software
1 affected component
Issabel Issabel
Remediation
Information
The vulnerabilities have been fixed by the Issabel team in the issabel-pbx module version 5.0.0-2 and in the issabel-agenda module version 5.0.0-4.
Event History
Oct 1, 2025
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-40647?
CVE-2025-40647 is considered to be a medium severity stored XSS vulnerability.
2
How do I fix CVE-2025-40647?
To fix CVE-2025-40647, ensure proper input validation and sanitization for the 'email' parameter in the application.
3
Which versions of Issabel are affected by CVE-2025-40647?
CVE-2025-40647 affects Issabel version 5.0.0.
4
What type of vulnerability is CVE-2025-40647?
CVE-2025-40647 is a stored Cross-Site Scripting (XSS) vulnerability.
5
Where is the vulnerability CVE-2025-40647 located?
CVE-2025-40647 is located in the '/index.php?menu=address_book' component of Issabel.