L
ogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN77560819/ | Third Party Advisory |
| https://www.logstare.com/vulnerability/2025-001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Dec 2025, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:secuavail:logstare_collector:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| First Time |
Microsoft
Secuavail Secuavail logstare Collector Linux linux Kernel Microsoft windows Linux |
|
| References | () https://jvn.jp/en/jp/JVN77560819/ - Third Party Advisory | |
| References | () https://www.logstare.com/vulnerability/2025-001/ - Vendor Advisory |
21 Nov 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-21 07:15
Updated : 2025-12-05 15:34
NVD link : CVE-2025-61949
Mitre link : CVE-2025-61949
CVE.ORG link : CVE-2025-61949
JSON object : View
Products Affected
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')