Junglewise Threat Intelligence

CVE-2025-0607: Logo Software Logo Cloud improper output escaping

CVE-2025-0607 · Severity: medium · CVSS 4.3 · Published 2025-10-06

Technologies: Logo Software Inc. Logo Cloud, Logo Software Cloud. Vendors: Logo Software Inc., Logo Software.

Executive brief

Logo Cloud, a cloud-based business management platform, contains a security flaw that could be used to facilitate phishing attacks. An attacker can exploit this vulnerability to manipulate how information is displayed to users, potentially tricking them into revealing sensitive information or performing unauthorized actions. This could lead to unauthorized access to corporate accounts or the compromise of business data.

Technical details

A vulnerability classified as CWE-116 (Improper Encoding or Escaping of Output) exists in Logo Software Inc. Logo Cloud before version 2.57. The flaw allows an attacker with high privileges to inject content that is not properly sanitized before being rendered, facilitating phishing or potentially cross-site scripting (XSS) scenarios. Exploitation requires network reachability and some level of user interaction from the victim. Successful exploitation could allow an attacker to compromise the integrity or confidentiality of a user's session. The issue has been addressed in version 2.57.

Affected products

  • Logo Software Inc. Logo Cloud before 2.57

Timeline

  • 2025-10-06: advisory: Initial publication of the vulnerability advisory.

References

Related threats