Junglewise Threat Intelligence

CVE-2025-70365: Kiamo stored XSS in administrative interfaces

CVE-2025-70365 · Severity: medium · CVSS 5.4 · Published 2026-04-09

Executive brief

Kiamo, a customer interaction management platform, contains a security flaw in its administrative interface. An attacker with administrative access can save malicious scripts into certain data fields, such as user descriptions. When other staff members view these pages, the scripts execute in their browsers, potentially allowing the attacker to steal session cookies or perform unauthorized actions on their behalf.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Kiamo versions prior to 8.4 (and 8.3.1) due to improper output encoding of user-supplied input. The flaw is located in administrative interfaces, specifically within fields such as the 'description' field for user variables and developer sections. An authenticated attacker with administrative privileges can inject malicious JavaScript payloads that are stored on the server. When other users navigate to the affected administrative pages, the payload executes in their security context, enabling session cookie theft (e.g., kiamo_session) or unauthorized browser-side actions. The vendor has released patches in version 8.4 and the 8.3.1 branch.

Affected products

  • Kiamo Kiamo < 8.4 (and < 8.3.1)

Timeline

  • 2025-12-08: disclosed: Vulnerability discovered and vendor notified
  • 2025-12-18: patched: Fix released in Kiamo 8.4
  • 2026-04-09: advisory: CVE published

References

Related threats