In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under specific interaction conditions. Successful exploitation could lead to exposure of user data or unauthorized actions within the browser context.
CVSS
No CVSS.
References
Configurations
No configuration.
History
22 Jul 2025, 13:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Jul 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
21 Jul 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-21 14:15
Updated : 2025-07-22 13:06
NVD link : CVE-2025-6235
Mitre link : CVE-2025-6235
CVE.ORG link : CVE-2025-6235
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')