Executive brief
An attacker can craft a malicious link that, when clicked by a user, causes their browser to execute JavaScript code supplied by the attacker. This could allow an attacker to steal session cookies, perform actions on behalf of the user, or redirect them to phishing sites.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability where an attacker crafts a malicious URL containing unescaped JavaScript. When a legitimate user clicks the link, their browser executes the attacker's script. The vulnerability requires user interaction (clicking the link) and relies on the application failing to properly sanitize or encode user-supplied input in URL parameters. An attacker can exploit this to steal authentication tokens, perform unauthorized actions, or redirect users to malicious content. Patch availability is unknown from the provided advisory.
Timeline
- 2026-09-16: disclosed