Stored XSS Vulnerability in Partner Software Applications by Partner Software
CVE-2025-6078

5.4MEDIUM

Key Information:

Vendor
CVE Published:
2 August 2025

What is CVE-2025-6078?

The Partner Software and Partner Web applications enable authenticated users to input notes on a specific page. However, due to insufficient input sanitization, these applications allow users to insert HTML tags and JavaScript, making them susceptible to stored cross-site scripting (XSS). This vulnerability enables attackers to embed malicious scripts within user-added notes, potentially compromising user data and application integrity.

Affected Version(s)

Partner Web 4.32 < 4.32.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.