DriveLock Operations Center Cross-Site Scripting Vulnerability Allowing Session Takeover

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in DriveLock Operations Center (DOC) versions 25.1.2 and 25.1.4. This issue allows attackers to inject malicious scripts into the web interface, which can be executed in the context of the affected user. The exploitation of this vulnerability could lead to session hijacking and arbitrary code execution.

Impact

Exploitation of this vulnerability could result in session takeover and unauthorized code execution on behalf of the user.

Remediation

Users are advised to update to DriveLock version 25.1.5, which addresses this vulnerability. For optimal security, it is recommended to use the latest release of DriveLock.

Added: Dec 17, 2025, 8:17 PM
Updated: Dec 17, 2025, 9:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.