A stored Cross Site Scripting (XSS) vulnherability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeiter Portal 2.15.2.0 allows remote authenticated users to execute arbitrary JavaScript code in the web browser of other users via manipulation of the 'Inhalt' parameter of the '/SchwarzeBrett/Nachrichten/CreateNachricht' or '/SchwarzeBrett/Nachrichten/EditNachricht/' requests.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adata
Adata mitarbeiter Portal |
|
| CPEs | cpe:2.3:a:adata:mitarbeiter_portal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Adata
Adata mitarbeiter Portal |
Thu, 11 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross Site Scripting (XSS) vulnherability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeiter Portal 2.15.2.0 allows remote authenticated users to execute arbitrary JavaScript code in the web browser of other users via manipulation of the 'Inhalt' parameter of the '/SchwarzeBrett/Nachrichten/CreateNachricht' or '/SchwarzeBrett/Nachrichten/EditNachricht/' requests. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-11T16:48:33.677Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61074
Updated: 2025-12-11T16:48:24.734Z
Status : Analyzed
Published: 2025-12-09T16:17:59.957
Modified: 2025-12-16T19:17:03.617
Link: CVE-2025-61074
No data.
OpenCVE Enrichment
No data.