Junglewise Threat Intelligence

CVE-2025-5254: Kron Technologies Kron PAM Stored XSS

CVE-2025-5254 · Severity: medium · CVSS 6.1 · Published 2025-07-25

Executive brief

Kron PAM, a privileged access management solution used to secure and monitor administrative access to IT infrastructure, is vulnerable to a stored cross-site scripting (XSS) flaw. An attacker with high-level privileges can inject malicious scripts into the management interface that execute when other administrators view specific pages. This could lead to the unauthorized disclosure of sensitive session information or the modification of administrative settings.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Kron Technologies Kron PAM before version 3.7. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with high privileges (PR:H) can inject malicious scripts into the application's database, which are subsequently executed in the browser of other users—typically administrators—when they access the affected page. While the attack requires user interaction (UI:R), it can result in high impacts to confidentiality and integrity by allowing the attacker to hijack sessions or perform actions on behalf of other users. The issue is resolved in Kron PAM version 3.7.

Affected products

  • Kron Technologies Kron PAM before 3.7

Timeline

  • 2025-07-25: advisory: Initial disclosure by TR-CERT/USOM

References

Related threats