CVE-2020-25399: Mind Imind Server

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

Affected products

  • Mind Imind Server: up to and including 3.13.65

Published 2020-11-05. Last modified 2026-06-17.