Files
CVEs-PoC/2025/CVE-2025-1420.md
T
2025-09-29 21:09:30 +02:00

852 B

CVE-2025-1420

Description

Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack.This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

POC

Reference

No PoCs from references.

Github