Vivaldi United Group iCONTROL+ Server Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Vivaldi United Group iCONTROL+ Server, specifically in firmware version 4.7.8.0.eden and Logic version 5.32 and earlier. This vulnerability allows attackers to inject JavaScript payloads into the error or edit-menu-item parameters, which are then executed in the context of the victim's browser session.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, send a request to the iCONTROL+ Server interface with an injected script in the 'error' parameter. The server will reflect the script back in the response, executing it in the user's browser.

Added: Jul 29, 2025, 2:46 PM
Updated: Jul 29, 2025, 2:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.