Junglewise Threat Intelligence

CVE-2025-51053: Vedo Suite Project Vedo Suite XSS in /api_vedo/

CVE-2025-51053 · Severity: medium · CVSS 6.1 · Published 2025-08-06

Technologies: Vedo Suite Project Vedo Suite. Vendors: Vedo Suite Project.

Executive brief

A security vulnerability exists in Vedo Suite, a management software platform, specifically within its API component. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of login session information or the performance of unauthorized actions on behalf of the user.

Technical details

A reflected Cross-site Scripting (XSS) vulnerability exists in the /api_vedo/ endpoint of Vedo Suite version 2024.17. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit this by crafting a malicious URL and enticing a victim to visit it. Successful exploitation allows the execution of arbitrary JavaScript or HTML code within the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. Proof-of-concept exploits have been identified in public repositories.

Affected products

  • Vedo Suite Project Vedo Suite 2024.17

Timeline

  • 2025-08-06: advisory: Initial NVD publication date
  • 2025-08-06: disclosed: Vulnerability details and PoC shared publicly

References

Related threats