Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerability has been fixed by the Kubysoft team in the latest version of the software.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser. | |
| Title | Reflected Cross-Site Scripting (XSS) in Kubysoft | |
| First Time appeared |
Kubysoft
Kubysoft kubysoft |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:kubysoft:kubysoft:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Kubysoft
Kubysoft kubysoft |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-17T11:49:52.787Z
Reserved: 2025-09-23T10:24:09.538Z
Link: CVE-2025-59905
No data.
Status : Received
Published: 2026-02-16T10:16:07.390
Modified: 2026-02-16T10:16:07.390
Link: CVE-2025-59905
No data.
OpenCVE Enrichment
Updated: 2026-02-17T08:49:57Z
Weaknesses