The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.
References
Configurations
No configuration.
History
03 Jul 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-03 12:15
Updated : 2025-07-03 15:13
NVD link : CVE-2025-27448
Mitre link : CVE-2025-27448
CVE.ORG link : CVE-2025-27448
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')