PT-2026-48267 · Brian Ruf · Oscal-Gui
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OSCAL-GUI (affected versions not specified)
Description
Reflected cross-site scripting occurs when unauthenticated attackers execute arbitrary JavaScript in a victim's browser. This is achieved by injecting malicious input through the
project request parameter. Attackers can craft a malicious URL with unsanitized input that breaks out of the JavaScript string and HTML attribute context within the body onload event handler, triggering script execution when the link is visited.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oscal-Gui