Cross-Site Scripting Vulnerability in Logpoint Reporting Feature
CVE-2025-54316
4.9MEDIUM
What is CVE-2025-54316?
A vulnerability has been identified in Logpoint prior to version 7.6.0, which allows attackers to exploit the reporting system. By creating malicious custom Jinja templates, adversaries can chain built-in filter functions to craft cross-site scripting (XSS) payloads. These payloads can be executed via the Logpoint Report Template engine, posing a serious risk to the integrity of data and potentially allowing unauthorized access to sensitive information. It is essential for users to update to the latest version to mitigate this risk.
Affected Version(s)
Logpoint 0 < 7.6.0
