VYPR
Low severityNVD Advisory· Published May 21, 2025· Updated Apr 15, 2026

CVE-2025-1419

CVE-2025-1419

Description

Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack.

This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored XSS vulnerability in Konsola Proget's comment section, fixed in version 2.17.5, allows high-privileged users to inject malicious scripts.

Vulnerability

Overview

The comment section of Konsola Proget, a component of the Proget MDM suite, fails to properly sanitize user input. This flaw enables a high-privileged user to perform a Stored Cross-Site Scripting (XSS) attack, as described in the official CVE description.

Exploitation

Conditions

The attack requires an authenticated user with high privileges (e.g., an administrator or manager) who can post comments. The injected script is stored on the server and subsequently executed in the browsers of other users who view the affected comments, without requiring additional user interaction. The vulnerability is present in all versions of Proget before 2.17.5 [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript within the context of the victim's browser. This could lead to session hijacking, data theft, or further compromise of the MDM console, potentially affecting the management of mobile devices across an organization [2].

Mitigation

The vendor has addressed this issue in version 2.17.5 of the server-side component of Konsola Proget. Users are strongly advised to update to this patched version immediately [1]. No workarounds have been published.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.