CVE-2025-40648: Stored Cross-Site Scripting (XSS) vulnerability in Issabel products
Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper validation of user input, through the 'numeroconferencia' parameter in '/index.php?menu=conferencia'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40648?
CVE-2025-40648 is considered a high severity vulnerability due to its potential for stored Cross-Site Scripting (XSS) exploitation.
How do I fix CVE-2025-40648?
To fix CVE-2025-40648, ensure proper validation and sanitization of the 'numero_conferencia' parameter to prevent XSS attacks.
What systems are affected by CVE-2025-40648?
CVE-2025-40648 affects Issabel version 5.0.0 and potentially earlier versions.
What type of vulnerability is CVE-2025-40648?
CVE-2025-40648 is a stored Cross-Site Scripting (XSS) vulnerability.
What is the potential impact of exploiting CVE-2025-40648?
Exploitation of CVE-2025-40648 could allow attackers to execute arbitrary scripts in the context of a user's session, leading to data theft or account compromise.