CVE-2025-52358

A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session.
Configurations

No configuration.

History

31 Jul 2025, 18:42

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site scripting en Vivaldi United Group iCONTROL+ Server, incluyendo la versión de firmware 4.7.8.0.eden Logic 5.32 y anteriores. Este problema permite a los atacantes inyectar payloads de JavaScript en los parámetros "error" o "edit-menu-item", que se ejecutan en la sesión del navegador de la víctima.

29 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 14:15

Updated : 2025-07-31 18:42


NVD link : CVE-2025-52358

Mitre link : CVE-2025-52358

CVE.ORG link : CVE-2025-52358


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')