PT-2026-76828 · Pandora · Pandora

·

CVE-2026-75531

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pandora (affected versions not specified)
Description Stored cross-site scripting (XSS) occurs during the rendering of URL observables. A URL associated with an analyzed file is inserted directly into the inline JavaScript onclick handler of the Submit to Lookyloo action. Because the value is embedded within a JavaScript string inside an HTML attribute, an attacker can use specially crafted characters to break the string and inject arbitrary JavaScript code. This script executes in the context of the web application when a user interacts with the Submit to Lookyloo control, potentially allowing the attacker to access browser information or perform actions using the victim's authenticated session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75531

Affected Products

Pandora