Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2025-1420

Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack.

This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

  • Published: May 21, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-1420
  • Exploit:

No technical information available.