AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-0424

UNKNOWN · CVSS N/A EPSS 0.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-18 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It affects Java. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-0424
Severity
UNKNOWN
CVSS
N/A
EPSS
0.43%
Java

Original NVD Description

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement.