CVE-2025-41089 | Xibo Signage Xibo CMS up to 4.2.1 Clock Widget Configuration Name cross site scripting
A vulnerability, which was classified as problematic, was found in Xibo Signage Xibo CMS up to 4.2.1. This affects an unknown function of the component Clock Widget. Such manipulation of the argument Configuration Name leads to cross site scripting.
This vulnerability is documented as CVE-2025-41089. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.