CVE Explorer
CVE-2025-68927
Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing the <p> tag, an attacker can inject arbitrary HTML elements such as forms and images, which are then stored and rendered without proper sanitization. This can lead to phishing, CSR
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"libredesk","vendor":"abhinavxd","versions":[{"status":"affected","version":"< 0.8.6-beta"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:47aeb91ff257feef191c9877a0ee21fae03976f4a3d00140e4e81054a48ee065 · sha256:fcffada580791219… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.3,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:47aeb91ff257feef191c9877a0ee21fae03976f4a3d00140e4e81054a48ee065 · sha256:fcffada580791219… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:47aeb91ff257feef191c9877a0ee21fae03976f4a3d00140e4e81054a48ee065 · sha256:fcffada580791219… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/abhinavxd/libredesk/commit/270347849943ac6a43e9fd6ebdc99c71841900eb","tags":["x_refsource_MISC"],"url":"https://github.com/abhinavxd/libredesk/commit/270347849943ac6a43e9fd6ebdc99c71841900eb"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:47aeb91ff257feef191c9877a0ee21fae03976f4a3d00140e4e81054a48ee065 · sha256:fcffada580791219… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/abhinavxd/libredesk/security/advisories/GHSA-wh6m-h6f4-rjf4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:47aeb91ff257feef191c9877a0ee21fae03976f4a3d00140e4e81054a48ee065 · sha256:fcffada580791219… · /containers/adp/0/references/0
{"name":"https://github.com/abhinavxd/libredesk/security/advisories/GHSA-wh6m-h6f4-rjf4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/abhinavxd/libredesk/security/advisories/GHSA-wh6m-h6f4-rjf4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:47aeb91ff257feef191c9877a0ee21fae03976f4a3d00140e4e81054a48ee065 · sha256:fcffada580791219… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.