CVE-2025-49185 - CERT CVE
ID CVE-2025-49185
Sažetak The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source.
Reference
CVSS
Base: 5.5
Impact: 2.7
Exploitability:2.3
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Zadnje važnije ažuriranje 12-06-2025 - 16:06
Objavljeno 12-06-2025 - 14:15