VDB

CVE-2025-6078

CVE-2025-6078 PUBLISHED CVSS 5.400000095367432 MEDIUM

Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious JavaScript, leading to stored XSS (cross-site scripting).

EPSS 0.12% · 30.9th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.12%
30.9th percentile

Affected Products

VendorProductVersions
Partner SoftwarePartner Web4.32

Timeline

  • Aug 2, 2025 EPSS Score
  • Aug 2, 2025 CVE Published
  • Aug 2, 2025 PoC Published
  • Aug 11, 2025 EPSS Score
  • Aug 19, 2025 EPSS Score
  • Aug 28, 2025 EPSS Score
  • Sep 6, 2025 EPSS Score
  • Sep 14, 2025 EPSS Score
  • Sep 23, 2025 EPSS Score
  • Oct 2, 2025 EPSS Score
  • Oct 10, 2025 EPSS Score
  • Oct 19, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›