PT-2025-31203 · Logic+1 · Logic+1

Matjosephs

·

Published

2025-07-29

·

Updated

2025-07-29

·

CVE-2025-52358

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Vivaldi United Group iCONTROL+ Server versions 4.7.8.0.eden Logic 5.32 and earlier
Description A cross-site scripting issue exists in Vivaldi United Group iCONTROL+ Server. This allows attackers to inject JavaScript payloads into the error or edit-menu-item parameters, which are then executed in the victim’s browser session.
Recommendations Versions prior to 4.7.8.0.eden Logic 5.32 should be updated.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52358

Affected Products

Logic
Icontrol+ Server