CVE-2024-25831

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/02/2024
Last modified:
16/01/2025

Description

F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:f-logic:datacube3:1.0:*:*:*:*:*:*:*
cpe:2.3:h:f-logic:datacube3:-:*:*:*:*:*:*:*