5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request using the 'logo' parameter in '/api/v3/companies/<ID>/logo', which are then stored on the server and executed in the context of any user who accesses the compromised resource.
Basic Information
ID
CVE-2025-41084
Source
INCIBE
Published
Jan 20, 2026 at 09:14
Affected Product
Vendor
SESAME LABS, S.L
Product
Sesame
Version
all versions
Affected Versions
SESAME LABS, S.L Sesame all versions