PT-2025-41884 · Unknown · Sipass Integrated

CVE-2025-40772

·

Published

2025-10-14

·

Updated

2025-10-14

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiPass integrated versions prior to 3.0
Description The SiPass integrated server applications are susceptible to stored Cross-Site Scripting (XSS). Successful exploitation enables an attacker to inject malicious code that executes in other users' browsers when they access the affected page. This can lead to impersonation of other users and theft of session data, potentially resulting in unauthorized access and privilege escalation.
Recommendations Update SiPass integrated to version 3.0 or later.

Fix

LPE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40772

Affected Products

Sipass Integrated