Cross-Site Scripting Vulnerability in a Leading Web Application
CVE-2025-55062

4.8MEDIUM

Key Information:

Vendor

Priority

Status
Vendor
CVE Published:
29 December 2025

What is CVE-2025-55062?

This vulnerability involves the improper neutralization of input during the web page generation process, potentially allowing attackers to execute malicious scripts in the context of users' browsers. This flaw can lead to unauthorized actions being performed with users' credentials, data theft, and other harmful outcomes. It highlights the importance of implementing robust input validation and sanitization mechanisms within web applications to prevent such security risks.

Affected Version(s)

Web 23.0 and below

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dudu Moyal - Peersec
.