We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2597

Reflected Cross-Site Scripting (XSS) vulnerability in ITIUM 6050



Description

Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET and POST requests to the ‘/index.php’ endpoint and injecting code into the ‘id_session.

Reserved 2025-03-21 | Published 2025-03-21 | Updated 2025-03-21 | Assigner INCIBE


MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

5.5.5.2-b3526
affected

Credits

Ismael Pacheco Torrecilla finder

References

www.incibe.es/...site-scripting-xss-vulnerability-itium-6050

cve.org (CVE-2025-2597)

nvd.nist.gov (CVE-2025-2597)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2597

Support options

Helpdesk Chat, Email, Knowledgebase