Junglewise Threat Intelligence

CVE-2025-8695: Netcad NetGIS Server reflected XSS

CVE-2025-8695 · Severity: medium · CVSS 5.4 · Published 2025-09-05

Executive brief

Netcad NetGIS Server, a platform used for managing geographic information systems (GIS), is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. If a user clicks on a specially crafted link, an attacker could execute code in the user's browser, potentially leading to unauthorized actions or the theft of session information. This could compromise the integrity of the GIS data management interface for affected users.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Netcad NetGIS Server versions 5.2.4 through 22.08.2025. The flaw stems from CWE-79, where the application fails to properly sanitize input before reflecting it back to the user in a web response. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to bypass same-origin policy protections, though the reported CVSS impact is limited to low integrity and availability impacts.

Affected products

  • Netcad NetGIS Server 5.2.4 through 22.08.2025

Timeline

  • 2025-09-05: advisory: NVD published the vulnerability record.

References