CVE-2019-25312
Awaiting Analysis
Awaiting Analysis - Queue
Persistent XSS in InoERP 0.7.2 Comment Section Enables Cookie Theft
Publication date: 2026-02-11
Last updated on: 2026-03-02
Assigner: VulnCheck
Description
Description
InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| inoideas | inoerp | 0.7.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |