Junglewise Threat Intelligence

CVE-2025-4284: Rolantis Agentis Cross-Site Scripting vulnerability

CVE-2025-4284 · Severity: medium · CVSS 6.1 · Published 2025-07-22

Technologies: Rolantis Information Technologies Agentis. Vendors: Rolantis Information Technologies.

Executive brief

Rolantis Agentis, a business management platform, contains a security flaw that could allow an attacker to execute malicious scripts in a user's web browser. This occurs when the application fails to properly clean data provided by users before displaying it on a page. If exploited, an attacker could potentially steal session cookies, impersonate users, or modify the content of the web page as seen by the victim.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Rolantis Information Technologies Agentis versions prior to 4.32. The flaw encompasses both Reflected and DOM-based XSS variants, stemming from improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link or visiting a malicious website. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is addressed in version 4.32.

Affected products

  • Rolantis Information Technologies Agentis before 4.32

Timeline

  • 2025-07-22: disclosed
  • 2025-07-22: advisory

References

Related threats