Junglewise Threat Intelligence

CVE-2025-8668: E-Kalite Turboard Reflected XSS

CVE-2025-8668 · Severity: critical · CVSS 9.4 · Published 2026-02-11

Executive brief

Turboard, a business intelligence and data visualization platform, contains a security vulnerability that allows attackers to inject malicious scripts into the application. If exploited, an attacker could potentially hijack user sessions, manipulate data displays, or perform unauthorized actions on behalf of legitimate users. This could lead to a loss of data integrity and unauthorized access to sensitive business dashboards.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in E-Kalite Turboard versions from 2025.07 before 2026.02. The flaw stems from CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application fails to properly sanitize user-supplied input before reflecting it back into the web interface. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session theft or unauthorized data modification. The vendor has released mitigations in version 2026.02.

Affected products

  • E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard From 2025.07 before 2026.02

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: advisory
  • 2026-02-11: patched: Mitigations implemented in version 2026.02

References