CVE-2025-0746
A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the malicious URL.
Vendor
Product
CWE
Yayın Tarihi
2025-01-30 12:15:28
Güncelleme
2025-10-08 19:12:04
Source Identifier
cve-coordination@incibe.es
KEV Date Added
-