CVE-2025-27102 – “Obiba Agate Cross-Site Scripting (XSS)”

The following table lists the changes that have been made to the
CVE-2025-27102 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 17, 2025

    Action Type Old Value New Value
    Added Description Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user’s first and last name. This HTML is then rendered in the email sent to administrative users. The Agate service account sends this email and appears trustworthy, making this a significant risk for phishing attacks. Administrative users are impacted, as they can be targeted by unauthenticated users. Version 3.3.0 fixes the issue.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-79
    Added Reference https://github.com/obiba/agate/releases/tag/3.3.0
    Added Reference https://github.com/obiba/agate/security/advisories/GHSA-v3wj-7vj5-xj5v
  • CVE Modified
    by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Mar. 17, 2025

    Action Type Old Value New Value
    Added Reference https://github.com/obiba/agate/security/advisories/GHSA-v3wj-7vj5-xj5v
Share the Post:

Related Posts