PT-2026-76907 · Unknown · Velociraptor
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Velociraptor (affected versions not specified)
Description
The web GUI allows the specification of custom column types for tables. When the URL type is used, the system forms a clickable link from the cell value. Because the code does not restrict the allowed URL schemes, an attacker can use a JavaScript scheme to execute a Cross-Site Scripting (XSS) attack, which occurs when malicious scripts are injected into trusted websites.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velociraptor