Cross-Site Scripting Vulnerability in ESAFENET CDG V5
CVE-2025-0790
5.3MEDIUM
What is CVE-2025-0790?
A cross-site scripting vulnerability has been discovered in ESAFENET CDG V5, specifically within the /doneDetail.jsp file. This vulnerability arises due to improper handling of the 'curpage' argument, allowing attackers to execute arbitrary scripts in the context of a user's session. The exploitation of this vulnerability can be initiated remotely, increasing the risk of unauthorized access to sensitive information. This issue has been publicly disclosed, and despite attempts to inform the vendor, there has been no response regarding mitigation.
Affected Version(s)
CDG V5