CVE-2025-40633

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/05/2025
Last modified:
21/05/2025

Description

A Stored Cross-Site Scripting (XSS) vulnerability has been found in <br /> Koibox for versions prior to e8cbce2. This vulnerability allows an <br /> authenticated attacker to upload an image containing malicious <br /> JavaScript code as profile picture in the <br /> &amp;#39;/es/dashboard/clientes/ficha/&amp;#39; endpoint