Aller au contenu

Fiche vulnérabilité

CVE-2025-49191 : faille moyenne sick field analytics (CVSS 6.1)

Description

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
12 juin 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • sick field analytics

Références

Rechercher une autre vulnérabilité dans la base CVE