Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5921 | A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component. |
| Link | Providers |
|---|---|
| https://github.com/sysentr0py/CVEs/tree/main/CVE-2025-25476 |
|
Wed, 09 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Syspass
Syspass syspass |
|
| CPEs | cpe:2.3:a:syspass:syspass:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Syspass
Syspass syspass |
Tue, 04 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 28 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-04T15:46:52.495Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25476
Updated: 2025-03-04T15:46:36.435Z
Status : Analyzed
Published: 2025-02-28T23:15:11.063
Modified: 2025-07-09T19:30:21.313
Link: CVE-2025-25476
No data.
OpenCVE Enrichment
No data.
EUVD