A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vivaldi
Vivaldi icontrol+ Server |
|
Vendors & Products |
Vivaldi
Vivaldi icontrol+ Server |
Tue, 29 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 29 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-29T00:00:00.000Z
Updated: 2025-07-29T13:55:44.521Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52358

Updated: 2025-07-29T13:54:35.623Z

Status : Received
Published: 2025-07-29T14:15:37.007
Modified: 2025-07-29T14:15:37.007
Link: CVE-2025-52358

No data.