Junglewise Threat Intelligence

CVE-2025-2405: Verisay Titarus cross-site scripting vulnerability

CVE-2025-2405 · Severity: high · CVSS 7.6 · Published 2025-12-25

Executive brief

A cross-site scripting (XSS) vulnerability has been identified in Titarus, a software platform developed by Verisay. This flaw allows an attacker to inject malicious scripts into the web interface, which could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information. Organizations using Titarus should update to version 2.144.4 or later to mitigate this risk.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Verisay Titarus versions prior to 2.144.4. The flaw stems from CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application fails to properly sanitize user-supplied input before rendering it in the browser. An authenticated attacker with low privileges can exploit this over the network to execute arbitrary JavaScript in the context of a victim's session. This can result in session hijacking, unauthorized modification of data, or partial loss of availability. The issue is resolved in version 2.144.4.

Affected products

  • Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus before 2.144.4

Timeline

  • 2025-12-25: advisory: Initial advisory published by TR-CERT/USOM
  • 2025-12-25: disclosed

References