CVE 6.9 MEDIUM

Cross-Site Scripting Vulnerability in QWC2 Registration GUI_CVE-2025-11184

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/RE:L

Description

Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31
allows an authorized attacker to plant arbitrary JavaScript code in the page

Basic Information

ID CVE-2025-11184
Source NCSC.ch
Published Oct 13, 2025 at 09:20

Affected Product

Vendor qwc-services
Product qwc-registration-gui
Affected Versions qwc-services qwc-registration-gui 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.