Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1990 | A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality. |
Solution
The reported vulnerability was fixed on 2 May 2024. The CSP (Content Security Policy) configuration implemented by Holded is designed to prevent the execution of inline scripts and restrict the uploading of scripts only to domains specified in its whitelist. This effectively mitigates script injection, as is the case with this vulnerability. There is currently no active risk associated with this vulnerability in the Holded platform.
Workaround
No workaround given by the vendor.
Thu, 06 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Feb 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality. | |
| Title | Stored Cross-Site Scripting vulnerability in Holded | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-02-13T13:47:45.237Z
Reserved: 2025-02-06T10:26:29.876Z
Link: CVE-2025-1076
Updated: 2025-02-06T14:15:17.104Z
Status : Received
Published: 2025-02-06T14:15:30.287
Modified: 2025-02-06T14:15:30.287
Link: CVE-2025-1076
No data.
OpenCVE Enrichment
No data.
EUVD