CVE-2025-63416
- EPSS 0.07%
- Veröffentlicht 05.11.2025 00:00:00
- Zuletzt bearbeitet 07.11.2025 19:47:41
** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated low-privileged attackers to execute arbitrary JavaScript in the context of other users' ...
CVE-2025-63417
- EPSS 0.07%
- Veröffentlicht 05.11.2025 00:00:00
- Zuletzt bearbeitet 07.11.2025 19:46:48
A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and ...
CVE-2025-63418
- EPSS 0.06%
- Veröffentlicht 05.11.2025 00:00:00
- Zuletzt bearbeitet 07.11.2025 19:45:54
A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitrary JavaScript in the context of a logged-in user's session by injecting payloads via the browser's developer console. The vulnerab...