CVE-2025-70844 is a Cross-Site Scripting (XSS) vulnerability in yaffa version 2.0.0 that allows attackers to inject malicious JavaScript through the "Add Account Group" function on the account-group page. When users view affected pages containing the injected script, the malicious code executes in their browser context, potentially compromising their session or stealing sensitive information. The vulnerability carries a Medium severity rating (CVSS 6.1) with a network-based attack vector requiring no authentication or special privileges. However, exploitation requires user interaction, as victims must view a page containing the injected payload. The impact is limited to low-level confidentiality and integrity compromise, with no availability impact. There is currently no evidence of active exploitation in the wild, and the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.0003 indicates minimal probability of exploitation, and community attention remains low. However, the vulnerability should still be addressed through patching to prevent potential abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:kantorge:yaffa:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.