Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perx Technologies
Perx Technologies customer Engagement & Loyalty Platform |
|
| Vendors & Products |
Perx Technologies
Perx Technologies customer Engagement & Loyalty Platform |
Mon, 27 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored cross-site scripting (XSS) vulnerability in the LMT Dashboard of the Perx Customer Engagement & Loyalty Platform allows an authenticated attacker to execute arbitrary JavaScript code in a victim's browser. The vulnerability is due to improper sanitization of SVG file uploads. An attacker can upload a malicious SVG file containing a script payload to a campaign. When another user views this image on the public LMT microsite, the script executes, which can lead to session hijacking, data theft, or other unauthorized actions.This issue affects Customer Engagement & Loyalty Platform before 4.617.4. | |
| Title | Stored Cross-Site Scripting in Perx Customer Engagement & Loyalty Platform | |
| Weaknesses | CWE-79 CWE-83 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2025-10-27T17:25:18.430Z
Reserved: 2025-10-13T12:22:34.611Z
Link: CVE-2025-11682
Updated: 2025-10-27T17:25:12.136Z
Status : Deferred
Published: 2025-10-27T08:15:36.220
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11682
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:04:07Z