CVE-2025-40633
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
20/05/2025
Last modified:
21/05/2025
Description
A Stored Cross-Site Scripting (XSS) vulnerability has been found in <br />
Koibox for versions prior to e8cbce2. This vulnerability allows an <br />
authenticated attacker to upload an image containing malicious <br />
JavaScript code as profile picture in the <br />
&#39;/es/dashboard/clientes/ficha/&#39; endpoint
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM



