Beveiligingsadvies

CVE-2025-1076

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-06 13:33:07
Laatst bijgewerkt 2025-02-13 13:47:45
Toegewezen door INCIBE
CVSS-score 4.8
Status PUBLISHED

Beschrijving

A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.