CVE-2020-25399: Mind Imind Server
High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
Affected products
- Mind Imind Server: up to and including 3.13.65
Published 2020-11-05. Last modified 2026-06-17.