CVE-2025-67438: Sync-In Server
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to execute arbitrary JavaScript in a victim's browser. By uploading a crafted SVG file containing a malicious payload, an attacker can access and exfiltrate sensitive information, including the user's session cookies.
Affected products
- Sync-In Sync-In Server: before 1.9.3 (fixed in 1.9.3)
Published 2026-02-20. Last modified 2026-06-17.