CVE-2025-59905
EUVD-2025-20698516.02.2026, 10:16
Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kubysoft | kubysoft | - |
𝑥
= Vulnerable software versions