CVE-2025-40633
20.05.2025, 11:15
A Stored Cross-Site Scripting (XSS) vulnerability has been found in Koibox for versions prior to e8cbce2. This vulnerability allows an authenticated attacker to upload an image containing malicious JavaScript code as profile picture in the '/es/dashboard/clientes/ficha/' endpoint
Awaiting analysis
This vulnerability is currently awaiting analysis.