MEDIUM
cronoh NanoVault xrb URL main.js executeJavaScript cross site scripting
Published Aug 5, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.44%
Description
A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.2.0StatusaffectedConstraints-
- Version 1.2.1StatusaffectedConstraints-
- Version
- ≤ 1.2.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://drive.google.com/file/d/1Hil-UQiLweGe9q1aCiiyQoiW9wOJsY7-/view?usp=drive_link broken-linkexploitPermissions Required
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23580 Advisory
- https://gist.github.com/jackfromeast/1e2e206813887a470e00b8474c616567 exploitrelatedThird Party Advisory
- https://vuldb.com/?ctiid.318665 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.318665 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.619142 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/file/d/1Hil-UQiLweGe9q1aCiiyQoiW9wOJsY7-/view?usp=drive_link | broken-linkexploitPermissions Required | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23580 | Advisory | |
| https://gist.github.com/jackfromeast/1e2e206813887a470e00b8474c616567 | exploitrelatedThird Party Advisory | |
| https://vuldb.com/?ctiid.318665 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.318665 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.619142 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 5, 2025
Updated Aug 5, 2025
Reserved Aug 4, 2025
Link CVE-2025-8535
CISA Vulnrichment
Updated Aug 5, 2025
ENISA EUVD
EUVD-2025-23580 Assigner VulDB
Published Aug 5, 2025
Updated Aug 5, 2025
Exploited since n/a
Link EUVD-2025-23580