PT-2026-76828 · Pandora · Pandora
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Pandora (affected versions not specified)
Description
Stored cross-site scripting (XSS) occurs during the rendering of URL observables. A URL associated with an analyzed file is inserted directly into the inline JavaScript onclick handler of the Submit to Lookyloo action. Because the value is embedded within a JavaScript string inside an HTML attribute, an attacker can use specially crafted characters to break the string and inject arbitrary JavaScript code. This script executes in the context of the web application when a user interacts with the Submit to Lookyloo control, potentially allowing the attacker to access browser information or perform actions using the victim's authenticated session.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora