XSS Vulnerability in DRACOON Branding Service Affects Customization Features
CVE-2025-53839

4MEDIUM

Key Information:

Vendor

Dracoon

Vendor
CVE Published:
15 July 2025

What is CVE-2025-53839?

The DRACOON Branding Service, designed for customizing file sharing interfaces, has a vulnerability affecting versions prior to 2.10.0. This XSS flaw allows malicious administrative input to inject harmful HTML code into the onboarding process for new users. This could lead to unauthorized actions or information exposure. A patch has been released in version 2.10.0, making it crucial for users to update to protect against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

security-advisories < 2.10.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.