CVE-2025-1420
21.05.2025, 13:16
Input provided in a field containing "activationMessage"in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in2.17.5 version ofKonsola Proget (server part of the MDM suite).
Awaiting analysis
This vulnerability is currently awaiting analysis.