CVE 7.4 HIGH

CVE-2025-40772_CVE-2025-40772

7.4 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Description

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page.

Successful exploitation allows an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation.

Basic Information

ID CVE-2025-40772
Source siemens
Published Oct 14, 2025 at 09:15

Affected Product

Vendor Siemens
Product SiPass integrated
Affected Versions Siemens SiPass integrated 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.