Junglewise Threat Intelligence

CVE-2025-57393: Kissflow Work Platform stored XSS in Kissflow Application

CVE-2025-57393 · Severity: high · CVSS 8.8 · Published 2025-10-01

Executive brief

Kissflow Work Platform, a popular business process and workflow automation tool, contains a security flaw that allows attackers to inject malicious scripts into web forms. When an administrator reviews these submitted forms, the script automatically runs in their browser, potentially allowing the attacker to steal login sessions, access sensitive business data, or take over administrative accounts. This could lead to a significant breach of corporate data and unauthorized changes to business workflows.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Kissflow Work Platform's Web Form Rendering Engine and Admin Review Module. The flaw is caused by improper input sanitization and output encoding of user-submitted form fields. An unauthenticated remote attacker can submit a crafted JavaScript payload through publicly accessible forms (such as account applications). When an administrator later views the submission within the Admin Panel, the payload executes, enabling session cookie theft, DOM exfiltration, and administrative account takeover. The vulnerability affects application versions prior to 7337 and Account Module versions 2.0 through 4.2.

Affected products

  • Kissflow Kissflow Application Versions before 7337 (Account Module v2.0 to v4.2)

Timeline

  • 2025-10-01: advisory: NVD and original researcher disclosure

References