CVE-2025-61949
CVE-2025-61949
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
21 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
LogStare Inc. · LogStare Collector (for Linux)LogStare Inc. · LogStare Collector (for Windows)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →