CVE Database
/

CVE-2025-40663

Back to search

CVE-2025-40663

Published: May 26, 2025

Modified: May 27, 2025

PUBLISHED

Description

Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated attacker to upload a malicious SVG image into the user's personal space in /CronosWeb/Modules/Persons/PersonalDocuments/PersonalDocuments. There is no reported fix at this time.

VendorProductVersions

i2A

Cronos

affected
23.02.01.17

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now