Security Advisory

CVE-2025-59904

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-02-16 09:55:53
Last updated 2026-02-17 16:56:22
Assigner INCIBE
CVSS score 5.1
State PUBLISHED

Description

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be injected and executed persistently in the context of users accessing the affected resource.