PT-2025-33950 · Unknown · Aelora Iframe Wrapper
Muhammad Yudha
·
Published
2025-08-20
·
Updated
2025-08-20
·
CVE-2025-49422
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Aelora iframe Wrapper versions n/a through 0.1.1
Description:
Aelora iframe Wrapper is susceptible to a DOM-Based Cross-Site Scripting issue due to improper neutralization of input during web page generation.
Recommendations:
Update Aelora iframe Wrapper to a version later than 0.1.1.
Fix
Incorrect Privilege Assignment
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aelora Iframe Wrapper