Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.
History

Thu, 12 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Description Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.
Title Dashboards and iFrames can link malicious web content
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published: 2025-06-12T14:08:02.756Z

Updated: 2025-06-12T14:12:22.866Z

Reserved: 2025-06-03T05:58:15.615Z

Link: CVE-2025-49191

cve-icon Vulnrichment

Updated: 2025-06-12T14:12:19.481Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-12T14:15:31.690

Modified: 2025-06-12T16:06:20.180

Link: CVE-2025-49191

cve-icon Redhat

No data.