CVE-2025-1987 Details
Description
A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type website_password and bookmark, as used in Bitdefender SecurePass. The client does not properly sanitize the URL field in these entries. As a result, an attacker can craft a malicious vault entry (or trick a user into creating or importing one) with a javascript:URL. When the user interacts with this entry (for example, by clicking or opening it), the application will execute the malicious JavaScript in the context of the Psono vault. This allows an attacker to run arbitrary code in the victim’s browser, potentially giving them access to the user’s password vault and sensitive data.
A Cross-Site Scripting (XSS) vulnerability exists in the Psono-Client component of Bitdefender SecurePass. This issue arises from improper sanitization of the URL field in vault entries categorized as website_password and bookmark. An attacker can create a malicious vault entry containing a javascript:URL, or persuade a user to create or import such an entry. When the user interacts with the entry, the application executes the embedded JavaScript within the context of the Psono vault. This exploitation could allow access to the user's password vault and sensitive information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bitdefender.com/support/support/security-advisories/stored-xss-in-psono-client-via-malicious-vault-entry-urls | [email protected] | Broken LinkVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| esaqa psono client | <= 4.0.4 |
CPE
Remediation
| |
| bitdefender securepass | < 0.0.76 < 1.0.10 < 1.1.8 < 1.1.18 < 1.1.22 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | Reanalysis | [email protected] |
| Jul 30, 2025 | Initial Analysis | [email protected] |
| Jun 21, 2025 | New CVE Received | [email protected] |