Junglewise Threat Intelligence

CVE-2025-2406: Verisay Trizbi Cross-Site Scripting

CVE-2025-2406 · Severity: high · CVSS 7.6 · Published 2025-12-25

Executive brief

A security vulnerability exists in Trizbi, a business management and communication platform. An attacker could inject malicious scripts into the system, potentially allowing them to modify data or gain unauthorized access to user sessions. This could lead to the disruption of business operations or the compromise of sensitive information handled by the platform.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Verisay Trizbi versions prior to 2.144.4. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this over the network to execute malicious scripts in the context of other users' browsers. According to the CVSS vector, the exploit can lead to high integrity impact and low confidentiality and availability impacts. Users are advised to upgrade to version 2.144.4 or later to remediate the vulnerability.

Affected products

  • Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi before 2.144.4

Timeline

  • 2025-12-25: disclosed
  • 2025-12-25: advisory

References