A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-1990 A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.
Fixes

Solution

The reported vulnerability was fixed on 2 May 2024. The CSP (Content Security Policy) configuration implemented by Holded is designed to prevent the execution of inline scripts and restrict the uploading of scripts only to domains specified in its whitelist. This effectively mitigates script injection, as is the case with this vulnerability. There is currently no active risk associated with this vulnerability in the Holded platform.


Workaround

No workaround given by the vendor.

History

Thu, 06 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
Description A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.
Title Stored Cross-Site Scripting vulnerability in Holded
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-02-13T13:47:45.237Z

Reserved: 2025-02-06T10:26:29.876Z

Link: CVE-2025-1076

cve-icon Vulnrichment

Updated: 2025-02-06T14:15:17.104Z

cve-icon NVD

Status : Received

Published: 2025-02-06T14:15:30.287

Modified: 2025-02-06T14:15:30.287

Link: CVE-2025-1076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses