← Back

CVE-2025-65300

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address fields (City, State, Country/Region) is rendered back to the page. Attackers can inject arbitrary JavaScript code, which executes when the affected profile page is viewed. This can lead to session hijacking, cookie theft, or arbitrary script execution in the victim's browser.

Affected (1)

Products: Coohom: Coohom
1 product
Coohom
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2025-10-28

References (3)

Source: cve@mitre.org
Permissions Required
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory

Timeline

No history available yet.