CVE-2025-63417

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and then executed in the context of other users' browsers when they view the malicious message, potentially leading to session hijacking, account takeover, or other client-side attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:selfbest:selfbest:2023.3:*:*:*:*:*:*:*

History

07 Nov 2025, 19:46

Type Values Removed Values Added
CPE cpe:2.3:a:selfbest:selfbest:2023.3:*:*:*:*:*:*:*
First Time Selfbest
Selfbest selfbest
References () https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea - () https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea - Exploit, Mitigation, Third Party Advisory

06 Nov 2025, 17:15

Type Values Removed Values Added
References () https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea - () https://rohitchaudhary045.medium.com/cve-2025-63417-the-chatroom-compromise-stored-xss-in-selfbest-platform-f34ddcd984ea -
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

05 Nov 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-05 19:16

Updated : 2025-11-07 19:46


NVD link : CVE-2025-63417

Mitre link : CVE-2025-63417

CVE.ORG link : CVE-2025-63417


JSON object : View

Products Affected

selfbest

  • selfbest
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')