Junglewise Threat Intelligence

CVE-2025-11960: Aryom Software KVKNET Reflected XSS

CVE-2025-11960 · Severity: medium · CVSS 6.1 · Published 2025-11-11

Executive brief

Aryom Software's KVKNET application contains a security vulnerability that could allow an attacker to execute malicious scripts in a user's browser. This occurs when the application fails to properly sanitize user-provided input before displaying it on a web page. If exploited, an attacker could potentially steal session cookies, hijack user accounts, or perform unauthorized actions on behalf of legitimate users.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Aryom Software High Technology Systems Inc. KVKNET versions prior to 2.1.8. The flaw is rooted in CWE-79, where the application fails to properly sanitize input before it is rendered in the web interface. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to credential theft or session hijacking. The issue has been addressed in version 2.1.8.

Affected products

  • Aryom Software High Technology Systems Inc. KVKNET before 2.1.8

Timeline

  • 2025-11-11: disclosed
  • 2025-11-11: advisory

References