Junglewise Threat Intelligence

CVE-2025-7760: Ofisimo Association Web Package Flora XSS via HTTP headers

CVE-2025-7760 · Severity: high · CVSS 7.6 · Published 2026-02-03

Executive brief

Ofisimo Association Web Package Flora, a software solution for managing association websites, contains a security flaw that allows attackers to inject malicious scripts through web requests. If exploited, this could allow an attacker to interfere with website operations, potentially leading to service disruptions or unauthorized actions within the application. The vendor has not yet responded to reports of this vulnerability.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Ofisimo Association Web Package Flora versions v3.0 through 03022026. The flaw is caused by improper neutralization of input provided within HTTP headers during web page generation. An attacker with low-privileged network access can exploit this to inject malicious scripts. According to the CVSS metrics provided by TR-CERT, the vulnerability has a high impact on availability (A:H) in addition to low impacts on confidentiality and integrity. No official patch has been confirmed as the vendor did not respond to the disclosure.

Affected products

  • Ofisimo Web-Based Software Technologies Association Web Package Flora v3.0 through 03022026

Timeline

  • 2026-02-03: advisory: Initial disclosure by TR-CERT/USOM

References