Junglewise Threat Intelligence

CVE-2025-0878: Akinsoft LimonDesk Cross-Site Scripting

CVE-2025-0878 · Severity: medium · CVSS 4.7 · Published 2025-09-03

Technologies: AKINSOFT LimonDesk. Vendors: AKINSOFT.

Executive brief

Akinsoft LimonDesk, a customer support and desk management software, contains a security vulnerability that could allow an attacker to inject malicious scripts into the application. If exploited, this could lead to unauthorized actions being performed in the context of a user's session or the theft of sensitive information. The risk is mitigated by the fact that an attacker would typically need high-level administrative privileges to perform the exploit.

Technical details

A stored or reflected Cross-Site Scripting (XSS) vulnerability exists in Akinsoft LimonDesk versions s1.02.14 through v1.02.17. The flaw stems from CWE-79, where the application fails to properly sanitize user-supplied input before rendering it in the web interface. An attacker with high privileges (PR:H) can exploit this over the network without user interaction to execute arbitrary JavaScript in the browser of other users. This could lead to session hijacking or unauthorized data modification. Users are advised to update to version 1.02.17 or later to remediate the issue.

Affected products

  • Akinsoft LimonDesk s1.02.14 to v1.02.17

Timeline

  • 2025-09-03: advisory: NVD publication date
  • 2025-09-03: disclosed: Initial disclosure by TR-CERT (USOM)

References

Related threats