7.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Description
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
Basic Information
ID
CVE-2026-5301
Source
GitLab
Published
Apr 8, 2026 at 12:04
Modified
Apr 8, 2026 at 16:02
Affected Product
Vendor
CoolerControl
Product
coolercontrol-ui
Version
2.0.0
Affected Versions
CoolerControl coolercontrol-ui 2.0.0