Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-apt-cacher-ng | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-29 10:15
Updated : 2025-10-16 15:54
NVD link : CVE-2025-11146
Mitre link : CVE-2025-11146
CVE.ORG link : CVE-2025-11146
JSON object : View
Products Affected
apt-cacher-ng_project
- apt-cacher-ng
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
