Executive brief
SVXportal, a dashboard for SVXLink radio nodes, contains a security flaw in its logging page. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions or the unauthorized modification of information displayed on the portal.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in SVXportal versions 2.5 and earlier. The vulnerability is located in the 'log.php' component, where the 'search' query parameter is embedded directly into an HTML input value attribute without proper sanitization. An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to capture session cookies or perform actions on behalf of the user. As of the advisory date, users are advised to check for updates or manually sanitize input in log.php.
Affected products
- sa2blv SVXportal <= 2.5
Timeline
- 2026-02-20: advisory: Initial advisory published by VulnCheck
- 2026-02-20: disclosed