Junglewise Threat Intelligence

CVE-2025-8308: Key Software Solutions INFOREX XSS via HTTP headers

CVE-2025-8308 · Severity: medium · CVSS 6.3 · Published 2026-02-18

Executive brief

Key Software Solutions Inc. INFOREX, a general information management system, contains a security vulnerability that could allow attackers to execute malicious scripts in a user's browser. This occurs when the system fails to properly clean data received through web requests. If exploited, an attacker could potentially steal session information, redirect users to fraudulent websites, or perform unauthorized actions on behalf of a legitimate user.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the INFOREX General Information Management System due to improper neutralization of input during web page generation. Specifically, the application fails to sanitize data provided in HTTP headers before reflecting it in the response. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted link or by manipulating headers in a way that triggers script execution in the victim's browser context. This can lead to session hijacking or unauthorized data modification. As of the disclosure date, the vendor has not responded to reports of this vulnerability.

Affected products

  • Key Software Solutions Inc. INFOREX- General Information Management System Versions from 2025 through 18022026

Timeline

  • 2026-02-18: advisory: Initial disclosure by USOM/TR-CERT
  • 2026-02-18: disclosed: NVD publication date

References