Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability

Vulnerability

A cross-site scripting vulnerability allowing remote code execution has been identified in Heimdall Data Database Proxy. This issue arises from improper validation of user-supplied data in the database event logs, enabling the injection of arbitrary scripts. Exploitation of this vulnerability requires minimal user interaction and allows attackers to execute code in the context of the targeted user.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.

Remediation

Users can upgrade to release build 25.03.01.10 to address this vulnerability.

Added: Nov 6, 2025, 9:58 PM
Updated: Nov 6, 2025, 9:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.