Stored Cross-Site Scripting Vulnerability in desknet's NEO by Desknet
CVE-2025-55072
What is CVE-2025-55072?
A stored cross-site scripting (XSS) vulnerability has been identified in desknet's NEO, versions V2.0R1.0 through V9.0R2.0. This flaw allows attackers to inject arbitrary JavaScript code into the affected system. When unsuspecting users interact with the compromised application, their web browsers execute the injected scripts, potentially leading to unauthorized access to sensitive information or the manipulation of user sessions. It is crucial for users and organizations utilizing desknet's NEO to apply the necessary security updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
desknet's NEO V2.0R1.0 to V9.0R2.0
References
CVSS V4
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
