Junglewise Threat Intelligence

CVE-2025-15437: LigeroSmart XSS in Environment Variable Handler

CVE-2025-15437 · Severity: low · CVSS 3.5 · Published 2026-01-02

Executive brief

LigeroSmart, an IT service management platform, is vulnerable to a security flaw where malicious scripts can be injected into the application. An attacker could use this to perform unauthorized actions in a user's browser, potentially leading to the theft of session information or sensitive data. This issue is resolved by upgrading to version 6.1.26 or 6.3.

Technical details

A cross-site scripting (XSS) vulnerability exists in LigeroSmart versions up to 6.1.24 due to improper sanitization of the REQUEST_URI environment variable. The vulnerability is located within the Environment Variable Handler, specifically affecting the Agent, Customer, and Public web interfaces. A remote attacker with low privileges can exploit this by crafting a malicious URL that, when visited by another user, executes arbitrary JavaScript in their browser. This can lead to session hijacking or unauthorized data access. The issue has been addressed in versions 6.1.26 and 6.3 by implementing proper sanitization of the REQUEST_URI argument.

Affected products

  • LigeroSmart LigeroSmart up to 6.1.24

Timeline

  • 2025-12-18: disclosed: Issue reported on GitHub and patch released
  • 2026-01-02: advisory: CVE published to NVD

References