We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.
Reserved 2025-04-16 | Published 2025-07-21 | Updated 2025-07-21 | Assigner CERTVDECWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
F. Bruckmoser, M. Eder, J. Heigl, M. Heudorn, G. Hofmarcher, M. Kadlec, M. Pristauz-Telsnigg, S. Resch, P. Schweinzer, M. Gschiel from St. Poelten UAS
certvde.com/de/advisories/VDE-2025-058
Support options