desknet's NEO Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in desknet's NEO versions through 9.0R2.0. This vulnerability allows the execution of arbitrary JavaScript in the web browser of a user accessing the application.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the user's web browser.

Remediation

Users are advised to update desknet's NEO to version 9.5 R1.0 or later. For those using the PostgreSQL or SQL Server versions, download and install the update module. Oracle version users should contact NEOJAPAN for guidance.

Added: Oct 16, 2025, 10:21 AM
Updated: Oct 16, 2025, 3:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
4.6
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.