CVE 5.1 MEDIUM

Stored Cross-Site Scripting (XSS) in Sesame web application_CVE-2025-41084

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request using the 'logo' parameter in '/api/v3/companies/<ID>/logo', which are then stored on the server and executed in the context of any user who accesses the compromised resource.

Basic Information

ID CVE-2025-41084
Source INCIBE
Published Jan 20, 2026 at 09:14

Affected Product

Vendor SESAME LABS, S.L
Product Sesame
Version all versions
Affected Versions SESAME LABS, S.L Sesame all versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.