A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address fields (City, State, Country/Region) is rendered back to the page. Attackers can inject arbitrary JavaScript code, which executes when the affected profile page is viewed. This can lead to session hijacking, cookie theft, or arbitrary script execution in the victim's browser.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coohom
Coohom coohom |
|
| CPEs | cpe:2.3:a:coohom:coohom:2025-10-28:*:*:*:*:*:*:* | |
| Vendors & Products |
Coohom
Coohom coohom |
Thu, 11 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address fields (City, State, Country/Region) is rendered back to the page. Attackers can inject arbitrary JavaScript code, which executes when the affected profile page is viewed. This can lead to session hijacking, cookie theft, or arbitrary script execution in the victim's browser. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-11T19:37:29.852Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65300
Updated: 2025-12-11T19:15:05.979Z
Status : Analyzed
Published: 2025-12-09T19:15:49.410
Modified: 2025-12-16T19:57:18.740
Link: CVE-2025-65300
No data.
OpenCVE Enrichment
No data.