Junglewise Threat Intelligence

CVE-2025-6396: Webbeyaz Website Design Website Software Cross-Site Scripting

CVE-2025-6396 · Severity: medium · CVSS 6.1 · Published 2025-09-26

Executive brief

Webbeyaz Website Design's website software contains a security flaw that allows for cross-site scripting (XSS). This vulnerability could allow an attacker to run malicious scripts in the browsers of people visiting the website. If exploited, this could lead to the theft of user session information, unauthorized access to user accounts, or the defacement of the website's content.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Webbeyaz Website Design Website Software due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is reachable over the network and requires no special privileges, though it does require interaction from a victim user (typically clicking a malicious link). An attacker can exploit this to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking, cookie theft, or unauthorized actions performed on behalf of the user. The issue is confirmed to affect software versions released through 2025.07.14.

Affected products

  • Webbeyaz Website Design Website Software through 2025.07.14

Timeline

  • 2025-09-26: disclosed
  • 2025-09-26: advisory

References