CVE-2025-40992: Stored XSS in Creativeitem Sociopro
Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/sociopro/profile/updateprofile', affecting to 'name' parameter via POST. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her cookie session details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40992?
CVE-2025-40992 is classified as a Stored XSS vulnerability, which poses significant security risks if exploited.
How do I fix CVE-2025-40992?
To fix CVE-2025-40992, ensure proper validation and sanitization of user inputs for the 'name' parameter in the '/sociopro/profile/update_profile' endpoint.
Who is affected by CVE-2025-40992?
CVE-2025-40992 affects users of Creativeitem Sociopro who utilize the profile update functionality without proper input validation.
What potential impact does CVE-2025-40992 have?
CVE-2025-40992 could allow an attacker to execute malicious scripts in the browser of a user who views the compromised profile.
When was CVE-2025-40992 reported?
CVE-2025-40992 was reported recently and highlights ongoing security issues within Creativeitem Sociopro products.