CVE-2025-9913: Cross Site Scripting: Session Hijacking
Published Oct 6, 2025
·Updated
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.
Affected Software
4 affected components
SICK Baggage Analytics
SICK Logistic Diagnostic Analytics
SICK Package Analytics
SICK Tire Analytics
Remediation
Information
It is strongly recommended to update the product to version 4.6.3.
Event History
Oct 6, 2025
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-9913?
CVE-2025-9913 has a high severity rating due to its potential for session hijacking through Cross Site Scripting.
2
How do I fix CVE-2025-9913?
To fix CVE-2025-9913, ensure proper sanitization and validation of user inputs in the dashboard functionality.
3
What software versions are affected by CVE-2025-9913?
CVE-2025-9913 affects various versions of SICK Baggage Analytics, Logistic Diagnostic Analytics, Package Analytics, and Tire Analytics.
4
What types of attacks can CVE-2025-9913 enable?
CVE-2025-9913 can enable Cross Site Scripting attacks that may lead to session hijacking.
5
Is it safe to use the "Open in new Tab" button in applications affected by CVE-2025-9913?
Using the "Open in new Tab" button is not safe in applications affected by CVE-2025-9913 without applying proper security measures.