CVE-2019-25265: Bigprof Online Inventory Manager
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.
Affected products
- Bigprof Online Inventory Manager: version 3.2 only
Published 2026-02-03. Last modified 2026-06-17.