Junglewise Threat Intelligence

CVE-2025-0420: Paraşüt Software Paraşüt Cross-Site Scripting

CVE-2025-0420 · Severity: medium · CVSS 4.7 · Published 2025-09-17

Executive brief

Paraşüt, a popular Turkish financial management and e-invoicing platform, contains a security vulnerability that could allow unauthorized script execution. An attacker with high-level administrative privileges can inject malicious code into the web interface, potentially leading to the theft of session information or unauthorized actions within the application. This could compromise the integrity of financial data or lead to unauthorized access to sensitive business records.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Paraşüt Software Paraşüt versions 0.0.0.65efa44e through 20250204. The flaw stems from CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application fails to properly sanitize input before rendering it in the browser. An attacker with high privileges (PR:H) can exploit this over the network without user interaction (UI:N) to execute arbitrary scripts in the context of a user's session. This can result in a partial loss of confidentiality, integrity, and availability.

Affected products

  • Paraşüt Software Paraşüt 0.0.0.65efa44e through 20250204

Timeline

  • 2025-09-17: disclosed: Initial NVD publication date

References