PT-2026-52630 · Unknown · Pen Drive Report Generator
CVSS v3.1
6.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pen Drive report generator (affected versions not specified)
Description
An issue exists where cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. This allows an attacker with cluster administrator privileges to inject a stored cross-site scripting (XSS) payload—a technique where malicious scripts are permanently stored on a target server—into cluster objects, such as the
spec.channel variable of the ClusterVersion. The script then executes in the browser of any user who opens the generated HTML report.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pen Drive Report Generator