LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN77560819/ | Third Party Advisory |
| https://www.logstare.com/vulnerability/2025-001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 Dec 2025, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:secuavail:logstare_collector:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| First Time |
Linux
Microsoft windows Microsoft Secuavail Secuavail logstare Collector Linux linux Kernel |
|
| References | () https://jvn.jp/en/jp/JVN77560819/ - Third Party Advisory | |
| References | () https://www.logstare.com/vulnerability/2025-001/ - Vendor Advisory |
21 Nov 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-21 07:15
Updated : 2025-12-05 15:34
NVD link : CVE-2025-61949
Mitre link : CVE-2025-61949
CVE.ORG link : CVE-2025-61949
JSON object : View
Products Affected
secuavail
- logstare_collector
microsoft
- windows
linux
- linux_kernel
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
