Executive brief
CobbleStone Enterprise Contract Management Portal, a platform used by organizations to manage legal agreements and procurement workflows, contains a security vulnerability in its chat box feature. An attacker can inject malicious scripts into the chat component that execute when other users view the conversation. This could lead to unauthorized actions being performed in the context of a victim's session or the theft of sensitive information displayed within the portal.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat box component of CobbleStone Enterprise Contract Management Portal v.22.4.0. The application fails to properly neutralize user-supplied input before storing it and rendering it to other users. An authenticated attacker with low privileges can inject malicious JavaScript into a chat session; when a victim (such as an administrator or another user) views the chat, the script executes in their browser context. This can be used to hijack sessions, bypass CSRF protections, or access sensitive contract data. The vendor has disputed the report's current relevance, stating the affected version is obsolete and no longer in circulation.
Affected products
- CobbleStone Software Enterprise Contract Management Portal 22.4.0
Timeline
- 2025-10-17: advisory: Initial disclosure of CVE-2025-56320
- 2026-03-04: other: Vulnerability marked as disputed by the vendor