Executive brief
Dolusoft Omaspot, a hosted service, contains a security flaw that allows for reflected cross-site scripting. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser session. This could lead to the theft of session cookies or sensitive information displayed within the application.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Dolusoft Omaspot versions prior to 12.09.2025. The application fails to properly sanitize or neutralize user-provided input before including it in dynamically generated web pages. An unauthenticated remote attacker can exploit this by crafting a malicious URL and persuading a victim to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking or unauthorized data access. The vulnerability is tracked as CWE-79.
Affected products
- Dolusoft Omaspot before 12.09.2025
Timeline
- 2025-09-16: disclosed
- 2025-09-16: advisory