Security Advisory

CVE-2025-61074

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-09 00:00:00
Last updated 2026-01-14 14:54:37
Assigner mitre
State PUBLISHED

Description

A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeiter Portal 2.15.2.0 allows remote authenticated users to execute arbitrary JavaScript code in the web browser of other users via manipulation of the Inhalt parameter of the /SchwarzeBrett/Nachrichten/CreateNachricht or /SchwarzeBrett/Nachrichten/EditNachricht/ requests.