PT-2025-49988 · Adata · Mitarbeiterportal

CVE-2025-61074

·

Published

2025-12-09

·

Updated

2025-12-22

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions adata Software GmbH Mitarbeiter Portal version 2.15.2.0
Description A stored Cross Site Scripting (XSS) issue exists in the bulletin board (SchwarzeBrett) component. This allows a remote authenticated user to execute arbitrary JavaScript code within the web browser of other users. The issue is triggered by manipulating the Inhalt parameter of the following API endpoints: '/SchwarzeBrett/Nachrichten/CreateNachricht' '/SchwarzeBrett/Nachrichten/EditNachricht/'
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the Inhalt parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61074

Affected Products

Mitarbeiterportal