CVE-2025-6078
Last modified
CVE-2025-6078 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious JavaScript, leading to stored XSS (cross-site scripting).. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious JavaScript, leading to stored XSS (cross-site scripting).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6078?
How severe is CVE-2025-6078?
How do I fix CVE-2025-6078?
Are you affected by CVE-2025-6078?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
