216.73.216.197

CVE-2025-15562

· Published 19/02/2026 11:15 · Modified 20/02/2026 21:19

Labels: CVE-2025-15562 2026-02-19551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2025-15562CWE-79

Essential information

Published
19/02/2026 11:15
Modified
20/02/2026 21:19
Author
Creator
CVSS
6.1 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / api cpe:2.3:a:*:api:*:*:*:*:*:*:*:*

References