CVE-2025-52344

Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject arbitrary JavaScript code on the user's browser via the Group name and Project Description input fields.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:explorance:blue:8.1.2:*:*:*:*:*:*:*

History

05 Feb 2026, 17:03

Type Values Removed Values Added
References () https://gist.github.com/SaraAlsaif/f363b307f29c865d499678eca3106b43 - () https://gist.github.com/SaraAlsaif/f363b307f29c865d499678eca3106b43 - Exploit, Mitigation, Third Party Advisory
References () https://www.explorance.com/products/blue - () https://www.explorance.com/products/blue - Product
First Time Explorance blue
Explorance
CPE cpe:2.3:a:explorance:blue:8.1.2:*:*:*:*:*:*:*

Information

Published : 2025-09-15 18:15

Updated : 2026-02-05 17:03


NVD link : CVE-2025-52344

Mitre link : CVE-2025-52344

CVE.ORG link : CVE-2025-52344


JSON object : View

Products Affected

explorance

  • blue
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')