PT-2025-39033 · Unknown · Mesh Connect Js Sdk

Publicado

2025-09-22

·

Atualizado

2025-09-22

·

CVE-2025-59430

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mesh Connect JS SDK versions prior to 3.3.2
Description Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. A lack of sanitization of URLs protocols in the createLink.openLink function enables the execution of arbitrary JavaScript code within the context of the parent page. This allows access to the parent page DOM, storage, session, and cookies. If an attacker can specify customIframeId, they can hijack the source of existing iframes.
Recommendations Update to Mesh Connect JS SDK version 3.3.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-59430
GHSA-VH3F-QPPR-J97F

Produtos afetados

Mesh Connect Js Sdk