GHSA-v9rv-vffq-wxpqMediumCVSS 5.4
Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS)...
🔗 CVE IDs covered (1)
📋 Description
Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2025-56320
- https://medium.com/@rajput.thakur/stored-xss-in-chat-box-component-cve-2025-56320-87fb10d809e2
- http://cobblestone.com
- http://enterprise.com
- https://www.cobblestonesoftware.com/products/enterprise-contract-management-software
- https://github.com/advisories/GHSA-v9rv-vffq-wxpq