Stored-XSS possibility in Namo CrossEditor4

CVE Details

Basic Information

Title Stored-XSS possibility in Namo CrossEditor4
Type cve
Published 2025-07-15T07:23:20.499Z
Modified 2025-07-15T07:23:20.499Z

Product Information

Vendor JiranSoft
Product CrossEditor4
Version 4.0.0.01

CVSS Information

Base Score 2.3 (LOW)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

AI Analysis

AI Description A stored XSS vulnerability in JiranSoft CrossEditor4 versions 4.0.0.01 to 4.6.0.23 could allow attackers to inject malicious scripts, potentially leading to unauthorized actions.
AI Severity Medium
AI Vendor JiranSoft
AI Product CrossEditor4
AI Version 4.0.0.01, 4.6.0.23

Affected Products

  • JiranSoft CrossEditor4 4.0.0.01

Additional Information

CWE List CWE-79, CWE-276
Source FSI

Description

The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentially allows Stored XSS.
This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.