LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN77560819/ | Third Party Advisory |
| https://www.logstare.com/vulnerability/2025-001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-11-21 07:15
Updated : 2025-12-05 15:34
NVD link : CVE-2025-61949
Mitre link : CVE-2025-61949
CVE.ORG link : CVE-2025-61949
JSON object : View
Products Affected
microsoft
- windows
linux
- linux_kernel
secuavail
- logstare_collector
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
