datacycle-engine dataCycle-CORE
- <= 25.07.3
A reflected DOM cross-site scripting vulnerability has been identified in dataCycle-CORE versions prior to 25.07.3. The issue arises in the core processing module, where an unauthenticated attacker can inject arbitrary HTML into flash notifications on public routes. This injected content is then rendered in the DOM using 'innerHTML', allowing the execution of malicious scripts. The vulnerability can be exploited by sending a crafted link to a public page, such as '/docs', as the affected JavaScript is loaded in the standard application layout, not restricted to admin views or debug pages.
Exploitation of this vulnerability allows for reflected DOM-based cross-site scripting, where injected HTML is executed as a script in the victim's browser.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.