LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
References
Configurations
No configuration.
History
21 Nov 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-21 07:15
Updated : 2025-11-21 15:13
NVD link : CVE-2025-61949
Mitre link : CVE-2025-61949
CVE.ORG link : CVE-2025-61949
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
