Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not properly sanitized. This allows to the attackers to embed malicious scripts in SVG files such as image profiles, which are then stored on the server and executed in the context of any user who accesses the compromised resource.
History

Tue, 25 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Taclia
Taclia taclia
Vendors & Products Taclia
Taclia taclia

Mon, 24 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 11:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not properly sanitized. This allows to the attackers to embed malicious scripts in SVG files such as image profiles, which are then stored on the server and executed in the context of any user who accesses the compromised resource.
Title Cross-Site Scripting (XSS) stored in Taclia's web application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-11-24T11:27:59.851Z

Updated: 2025-11-24T13:01:54.233Z

Reserved: 2025-04-16T09:09:36.724Z

Link: CVE-2025-41087

cve-icon Vulnrichment

Updated: 2025-11-24T13:01:50.318Z

cve-icon NVD

Status : Received

Published: 2025-11-24T12:15:46.117

Modified: 2025-11-24T12:15:46.117

Link: CVE-2025-41087

cve-icon Redhat

No data.