CVE-2025-1419
Description
Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack.
This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in Konsola Proget's comment section, fixed in version 2.17.5, allows high-privileged users to inject malicious scripts.
Vulnerability
Overview
The comment section of Konsola Proget, a component of the Proget MDM suite, fails to properly sanitize user input. This flaw enables a high-privileged user to perform a Stored Cross-Site Scripting (XSS) attack, as described in the official CVE description.
Exploitation
Conditions
The attack requires an authenticated user with high privileges (e.g., an administrator or manager) who can post comments. The injected script is stored on the server and subsequently executed in the browsers of other users who view the affected comments, without requiring additional user interaction. The vulnerability is present in all versions of Proget before 2.17.5 [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript within the context of the victim's browser. This could lead to session hijacking, data theft, or further compromise of the MDM console, potentially affecting the management of mobile devices across an organization [2].
Mitigation
The vendor has addressed this issue in version 2.17.5 of the server-side component of Konsola Proget. Users are strongly advised to update to this patched version immediately [1]. No workarounds have been published.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <2.17.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.