CVE-2019-25312

InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inoideas:inoerp:0.7.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-11 15:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25312

Mitre link : CVE-2019-25312

CVE.ORG link : CVE-2019-25312


JSON object : View

Products Affected

inoideas

  • inoerp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')