CVE-2025-41088: Stored Cross-Site Scripting (XSS) in CMS
Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text' field in the section with the malicious payload.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41088?
CVE-2025-41088 is rated as a high severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-41088?
To fix CVE-2025-41088, ensure that input validation is properly implemented throughout the Xibo CMS, especially in the 'Templates' and 'Global Elements' sections.
Who is affected by CVE-2025-41088?
CVE-2025-41088 affects all users of Xibo Signage's Xibo CMS version 4.1.2 that do not have mitigations in place for stored cross-site scripting.
What type of vulnerability is CVE-2025-41088?
CVE-2025-41088 is a stored cross-site scripting (XSS) vulnerability, which allows attackers to execute malicious scripts in the context of a user's session.
Is there a workaround for CVE-2025-41088?
Currently, there is no documented workaround for CVE-2025-41088, so updating to a secured version is recommended.