Medium severity6.3NVD Advisory· Published Jun 4, 2026· Updated Jun 5, 2026
CVE-2025-65640
CVE-2025-65640
Description
Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating a new document. Specifically, when an authenticated attacker submits data containing JavaScript code within these fields, the application fails to properly sanitize or escape the content. As a result, the injected script is executed when the page is rendered, allowing the attacker to execute arbitrary JavaScript in the context of other users' browsers who view the affected page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
- Range: =5.0.0.559
Patches
Vulnerability mechanics
References
1- www.arket.itnvd
News mentions
0No linked articles in our index yet.