CVE-2025-26514
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
19/09/2025
Última modificación:
19/09/2025
Descripción
*** Pendiente de traducción *** StorageGRID (formerly <br />
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are <br />
susceptible to a Reflected Cross-Site Scripting vulnerability. <br />
Successful exploit could allow an attacker to view or modify <br />
configuration settings or add or modify user accounts but requires the <br />
attacker to know specific information about the target instance and then<br />
trick a privileged user into clicking a specially crafted link.
Impacto
Puntuación base 3.x
6.40
Gravedad 3.x
MEDIA