Junglewise Threat Intelligence

CVE-2025-52169: agorum Software GmbH Agorum core open reflected XSS

CVE-2025-52169 · Severity: high · CVSS 7.1 · Published 2025-07-18

Executive brief

Agorum core open, an enterprise content management system used for document management and workflow automation, is vulnerable to a security flaw that allows attackers to execute malicious scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could steal login credentials, hijack active user sessions, or modify the appearance of the application. This issue affects several components of the platform, potentially compromising sensitive business documents and digital collaboration workflows.

Technical details

Agorum core open is affected by multiple reflected cross-site scripting (XSS) vulnerabilities due to improper input sanitization and output encoding across numerous JSP endpoints, including BeginSSOLogin.jsp, SSO.jsp, and several others. An unauthenticated remote attacker can exploit these flaws by crafting a malicious URL containing JavaScript in parameters such as 'userName' and persuading a victim to visit the link. If successful, the attacker's script executes within the context of the victim's browser session, allowing for session token theft (CWE-79). The vendor has addressed these systemic input handling issues in versions 11.9.2 and 11.10.1.

Affected products

  • agorum Software GmbH Agorum core open 11.9.1.3-1857 and earlier versions prior to 11.9.2 and 11.10.1

Timeline

  • 2025-05-05: disclosed: Vendor first contacted and confirmed receipt
  • 2025-05-15: patched: Vulnerability fixed in cloud instances
  • 2025-05-30: patched: Fixed versions 11.9.2 and 11.10.1 released for on-premise users
  • 2025-06-27: advisory: Initial researcher advisory published
  • 2025-07-18: advisory: NVD publication date

References