CVE-2025-41089: Reflected Cross-Site Scripting (XSS) in CMS
Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41089?
CVE-2025-41089 is classified as a medium severity level vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-41089?
To fix CVE-2025-41089, ensure proper validation and sanitization of user input in the Xibo CMS templates section.
Who is affected by CVE-2025-41089?
CVE-2025-41089 affects users of Xibo CMS version 4.1.2 and earlier, specifically those utilizing the Templates feature.
What type of vulnerability is CVE-2025-41089?
CVE-2025-41089 is a reflected cross-site scripting (XSS) vulnerability that allows attackers to execute scripts in the context of a user's browser.
Can CVE-2025-41089 be exploited remotely?
Yes, CVE-2025-41089 can be exploited remotely if an attacker tricks a user into opening a malicious link that leverages the XSS vulnerability.