CVE-2025-68876
7.1INVELITY · Invelity SPS connect
A Reflected Cross-site Scripting (XSS) vulnerability exists in the Invelity SPS connect plugin due to improper neutralization of user-supplied input during web page generation.
Executive summary
A Reflected Cross-site Scripting vulnerability in the Invelity SPS connect plugin allows unauthenticated attackers to execute malicious scripts in a user's browser session.
Vulnerability
The vulnerability is a Reflected Cross-site Scripting (CWE-79) flaw. It allows an unauthenticated attacker to inject malicious scripts into web pages generated by the plugin, which are then executed by the victim's browser.
Business impact
Successful exploitation of this vulnerability can lead to unauthorized actions performed on behalf of the user, session hijacking, or the theft of sensitive information stored within the browser. Given the CVSS score of 7.1, this represents a high risk for organizations relying on this plugin, as it could result in significant reputational damage and potential compromise of user accounts.
Remediation
Immediate Action: Monitor the vendor website for the release of a security update and apply it immediately upon availability. If a patch is not yet available, consider deactivating the plugin until a secure version is released.
Proactive Monitoring: Review web access logs for unusual URL parameters containing script tags or suspicious encoded characters that may indicate attempted XSS attacks.
Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block common XSS attack patterns targeting the plugin's endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations using the Invelity SPS connect plugin should prioritize moving to a patched version as soon as the vendor makes one available. Until such time, administrators should evaluate whether the plugin is essential for business operations and consider disabling it to eliminate the attack surface entirely.
More INVELITY CVEs
Sources
Originally found and disclosed by Nguyen Xuan Chien | Patchstack Bug Bounty Program, per the CVE Program record.