CVE-2025-41065
Last modified
CVE-2025-41065 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by inyecting a malicious payload through the 'Edit Batch Name' function. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by inyecting a malicious payload through the 'Edit Batch Name' function. THe payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-41065?
How severe is CVE-2025-41065?
How do I fix CVE-2025-41065?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4106An authenticated admin user with access to both the manageme…8.9
- CVE-2025-41060A vulnerability has been discovered in appRain CMF version 4…5.4
- CVE-2025-41061A vulnerability has been discovered in appRain CMF version 4…5.4
- CVE-2025-41062A vulnerability has been discovered in version 4.0.5 of appR…5.4
- CVE-2025-41063A vulnerability has been discovered in version 4.0.5 of appR…5.4
- CVE-2025-41064Incorrect authentication vulnerability in OpenSIAC, which co…9.3
- CVE-2025-41066Horde Groupware v5.2.22 has a user enumeration vulnerability…5.3
- CVE-2025-41067Reachable Assertion vulnerability in Open5GS up to version 2…7.5
- CVE-2025-41068Reachable Assertion vulnerability in Open5GS up to version 2…7.5
- CVE-2025-41069Insecure Direct Object Reference (IDOR) vulnerability in Dep…5.3
- CVE-2025-4107Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-41070Reflected Cross-site Scripting (XSS) vulnerability in Sanoma…4.8
Are you affected by CVE-2025-41065?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
