PT-2025-62951 · Pypi · Omero.Web

Published

2025-11-24

·

Updated

2025-11-24

CVSS v4.0

1.3

Low

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U

Impact

OMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks.

Patches

User should upgrade OMERO.web to 5.29.3 or higher.

Workarounds

None.

Resources

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-J4GV-6X9V-V23G

Affected Products

Omero.Web