Junglewise Threat Intelligence

CVE-2025-0609: Logo Software Logo Cloud XSS in web interface

CVE-2025-0609 · Severity: medium · CVSS 4.7 · Published 2025-10-06

Technologies: Logo Software Inc. Logo Cloud. Vendors: Logo Software Inc..

Executive brief

Logo Cloud, a business management and cloud services platform, is affected by a security vulnerability that could allow unauthorized script execution. An attacker with high-level administrative privileges can inject malicious code into the web interface. This could lead to the theft of session information or the manipulation of data within the application, potentially compromising business operations.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Logo Software Inc. Logo Cloud versions prior to 1.18. The flaw is rooted in CWE-79, where the application fails to properly neutralize user-supplied input before including it in generated web pages. An attacker with high privileges (PR:H) can exploit this over the network without user interaction (UI:N) to execute arbitrary scripts in the context of a user's browser. This can result in unauthorized access to sensitive information, session hijacking, or modification of web content. The vulnerability was addressed in version 1.18.

Affected products

  • Logo Software Inc. Logo Cloud before 1.18

Timeline

  • 2025-10-06: advisory: Initial publication of CVE-2025-0609

References