Executive brief
Aidango, a communication and information management platform, is affected by a security vulnerability that allows for cross-site scripting. An attacker with basic user access could inject malicious scripts into the web interface, potentially leading to unauthorized data modification or the hijacking of other users' sessions. This could compromise the integrity of the platform's data and the security of its users.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Verisay Aidango due to improper neutralization of user-supplied input during web page generation. The vulnerability is reachable over the network and requires low-level authentication (PR:L), but notably does not require user interaction (UI:N) according to the provided CVSS vector, suggesting a stored XSS variant. An attacker can exploit this to execute arbitrary scripts in the context of a victim's browser, potentially leading to session hijacking or unauthorized modification of application data. The issue is resolved in version 2.144.4.
Affected products
- Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango before 2.144.4
Timeline
- 2025-12-25: disclosed
- 2025-12-25: advisory