Skip to content

Security issues in v25.05

Moderate
wrongecho published GHSA-333p-5pf2-vfwc Aug 16, 2025

Package

No package listed

Affected versions

25.05

Patched versions

25.06

Description

Security issues in 25.05

We would like to extend our sincere thanks to @4rdr for responsibly disclosing security vulnerabilities in ITFlow version 25.05. Their contribution helped us patch the following issues in version 25.06:

  • SQL Injection vulnerability in the ticket filtering category variable
  • Cross Site Scripting (XSS) vulnerabilities in ticket subjects and contact names
  • XSS vulnerability in the URL field for custom links
  • XSS risk due to allowing XML file uploads

@4rdr - thank you for helping keep the ITFlow community safe.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits