A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and then executed in the context of other users' browsers when they view the malicious message, potentially leading to session hijacking, account takeover, or other client-side attacks.
References
| Link | Resource |
|---|---|
| https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea | Exploit Mitigation Third Party Advisory |
| https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea | Exploit Mitigation Third Party Advisory |
Configurations
History
07 Nov 2025, 19:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:selfbest:selfbest:2023.3:*:*:*:*:*:*:* | |
| First Time |
Selfbest
Selfbest selfbest |
|
| References | () https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea - Exploit, Mitigation, Third Party Advisory |
06 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea - | |
| CWE | CWE-79 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
05 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-05 19:16
Updated : 2025-11-07 19:46
NVD link : CVE-2025-63417
Mitre link : CVE-2025-63417
CVE.ORG link : CVE-2025-63417
JSON object : View
Products Affected
selfbest
- selfbest
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
