Junglewise Threat Intelligence

CVE-2025-0547: Paraşüt Software Bizmu XSS vulnerability

CVE-2025-0547 · Severity: medium · CVSS 4.7 · Published 2025-09-18

Executive brief

Paraşüt Software Bizmu, a business management and accounting platform, contains a security vulnerability that could allow an attacker to inject malicious scripts into web pages. If exploited, this could allow an attacker to perform unauthorized actions or access sensitive information within the context of a user's session. This issue primarily affects the Bizmu application between versions 2.27.0 and 20250212.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Paraşüt Software Bizmu versions 2.27.0 through 20250212. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). An attacker with high privileges can exploit this over the network to inject malicious scripts. According to the CVSS vector, the attack does not require user interaction (UI:N), which is unusual for standard XSS and may suggest a stored XSS variant where the payload executes automatically for other users. Successful exploitation can lead to a partial loss of confidentiality, integrity, and availability.

Affected products

  • Paraşüt Software Bizmu 2.27.0 through 20250212

Timeline

  • 2025-09-18: disclosed: Initial publication date

References