Vulnerability Description
Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious JavaScript, leading to stored XSS (cross-site scripting).
CVSS Score
MEDIUM
References
- https://partnersoftware.com/resources/software-release-info-4-32/
- https://kb.cert.org/vuls/id/317469
- https://www.kb.cert.org/vuls/id/317469
FAQ
What is CVE-2025-6078?
CVE-2025-6078 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, mak...
How severe is CVE-2025-6078?
CVE-2025-6078 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-6078?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.