Loading vulnerability details…
CVSS v3.1
4.5
EPSS
0.27%
Published
Oct 6, 2025
Modified
Jan 28, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:NWeaknesses (CWE)
Affected Products (4)
References (6)