216.73.216.233

CVE-2025-59430

· Published 22/09/2025 19:16 · Modified 22/09/2025 21:22

Labels: CVE-2025-59430 2025-09-22CVE-2025-59430CWE-79[email protected]

Essential information

Published
22/09/2025 19:16
Modified
22/09/2025 21:22
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

CVSS metrics

Description

Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitization of URLs protocols in the createLink.openLink function enables the execution of arbitrary JavaScript code within the context of the parent page. This is technically indistinguishable from a real page at the rendering level and allows access to the parent page DOM, storage, session, and cookies. If the attacker can specify customIframeId, they can hijack the source of existing iframes. This issue has been patched in version 3.3.2.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mesh connect / js sdk cpe:2.3:a:mesh_connect:js_sdk:<3.3.2:*:*:*:*:*:*:*

References