← Back

CVE-2025-67078

nvd nist
Published: Jan 15, 2026Modified: Mar 10, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.

Affected (1)

1 product
Agora Project
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 25.10

References (2)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.