PT-2026-65482 · Pivotick+1 · Pivotick
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Pivotick (affected versions not specified)
Description
A cross-site scripting issue exists in the inspect and edit node modals. Node labels and descriptions from graph data were interpolated directly into the HTML used for modal headers. An attacker capable of supplying or modifying graph data could insert malicious HTML or JavaScript payloads into a node label or description. These payloads are executed in the application origin when a user opens the affected node modals, potentially allowing the attacker to access victim information, modify data, or perform actions using the victim's active session.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pivotick