Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions between 3.2C and 5.1K. This vulnerability could allow an attacker to execute a JavaScript payload by making a POST request and injecting malicious code into the editable ‘username’ parameter of the ‘/PageLoginVisio.do’ endpoint.
History

Wed, 12 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Feb 2025 12:45:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions between 3.2C and 5.1K. This vulnerability could allow an attacker to execute a JavaScript payload by making a POST request and injecting malicious code into the editable ‘username’ parameter of the ‘/PageLoginVisio.do’ endpoint.
Title Cross-Site Scripting (XSS) vulnerability in Kelio Visio
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-02-10T12:42:26.693Z

Updated: 2025-02-12T15:43:14.698Z

Reserved: 2025-02-10T09:56:16.658Z

Link: CVE-2025-1175

cve-icon Vulnrichment

Updated: 2025-02-12T15:43:10.958Z

cve-icon NVD

Status : Deferred

Published: 2025-02-10T13:15:26.593

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-1175

cve-icon Redhat

No data.