Junglewise Threat Intelligence

CVE-2025-13505: Datateam Datactive Stored XSS in web page generation

CVE-2025-13505 · Severity: medium · CVSS 4.8 · Published 2025-12-02

Executive brief

Datateam Datactive, a business information management platform, contains a security vulnerability that allows attackers to inject malicious scripts into the application. If a user views a page containing this injected content, the script could execute in their browser, potentially leading to unauthorized access to their session or sensitive information. This could compromise the integrity of user accounts and the data they manage within the system.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Datateam Datactive versions 2.13.34 through 2.14.0.5. The flaw stems from the improper neutralization of script-related HTML tags (CWE-80) and general input during web page generation (CWE-79). An attacker can exploit this by submitting malicious JavaScript that is permanently stored on the server. When other users access the affected page, the script executes in their browser context. While the CNA reported a lower score requiring local network access and authentication, NIST's analysis suggests the vulnerability may be reachable over the network without prior authentication, provided there is user interaction. The issue is addressed in version 2.14.0.6.

Affected products

  • Datateam Information Technologies Inc. Datactive from 2.13.34 before 2.14.0.6

Timeline

  • 2025-12-02: disclosed
  • 2025-12-02: advisory

References