PatchSiren cyber security CVE debrief
CVE-2025-7760 Ofisimo Web-Based Software Technologies CVE debrief
CVE-2025-7760 is a high-severity vulnerability (CVSS Score: 7.6) affecting Ofisimo Web-Based Software Technologies Association Web Package Flora, specifically versions from v3.0 through 03022026. This vulnerability allows for Cross-site Scripting (XSS) through HTTP headers, potentially enabling attackers to inject malicious scripts into web pages viewed by other users.
- Vendor
- Ofisimo Web-Based Software Technologies
- Product
- Association Web Package Flora
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-03
- Original CVE updated
- 2026-06-05
- Advisory published
- 2026-02-03
- Advisory updated
- 2026-06-05
Who should care
Users of Ofisimo Web-Based Software Technologies Association Web Package Flora, particularly those using versions between v3.0 and 03022026, should be aware of this vulnerability and take necessary actions to mitigate potential risks.
Technical summary
The vulnerability is caused by improper neutralization of input during web page generation, allowing attackers to inject malicious scripts via HTTP headers. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H.
Defensive priority
HIGH
Recommended defensive actions
- Update to a version of Association Web Package Flora that is outside the affected range (from v3.0 through 03022026).
- Implement additional security measures to monitor and filter HTTP headers for potentially malicious input.
Evidence notes
The vendor, Ofisimo Web-Based Software Technologies Association, was contacted early about this disclosure but did not respond.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-7760 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-7760
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-7760 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-7760
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0015
-
Source reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-26-0015
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.